logo

Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem

ID: 4b8ba2af-8364-5342-8882-16f18e403bb2

STIX ID: report--4b8ba2af-8364-5342-8882-16f18e403bb2

Feed Name: Threat Intelligence

Threat Score
88/100

Date Published: 2025-11-17

Date Updated: 2026-04-27

Author: Mandiant

...
...

Mandiant observed UNC1549 conducting targeted campaigns that used reconnaissance-driven spear-phishing of IT and administrators to obtain elevated credentials, deployed multiple custom backdoors (MINIBIKE, TWOSTROKE, DEEPROOT), abused DLL search-order hijacking for stealth and persistence across legitimate applications, and operated a custom tunneler (LIGHTRAIL) leveraging cloud infrastructure; the report includes technical breakdowns of TWOSTROKE's C2 protocol and victim ID generation and differences between LIGHTRAIL and its LastenZug source.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.