Threadlinqs IntelligenceStart free

Threat actorIranTracked since 2026-06

TA455

Also known as:UNC1549Yellow Dev 13Charming KittenAPT35Mint SandstormCALANQUE

As of 2026-06-16, TA455 is a Iran-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning apt. Also known as UNC1549, Yellow Dev 13, Charming Kitten, APT35. ATT&CK coverage spans 46 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1036 (Masquerading), T1090 (Proxy).

Tracked threats
22 high
First seen
2026-06-10
Last seen
2026-06-16
ATT&CK techniques
46across 2 of 2 threats
Related CVEs
0None referenced
Attribution
IranNation or origin
Nation: Iran · 2 tracked threat(s) · Categories: APT

Activity timeline

TA455 appears in 2 tracked threats between and .

ATT&CK techniques observed

46 techniques observed across 2 of 2 tracked threats · Command and Control (7), Stealth (formerly Defense Evasion) (6), Credential Access (5), Initial Access (5), Execution (4), Resource Development (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
  • T1003.006 OS Credential Dumping: DCSync — Credential Accessobserved in 1 of 2 tracked threats
  • T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
  • T1018 Remote System Discovery — Discoveryobserved in 1 of 2 tracked threats
  • T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 2 tracked threats
  • T1027.001 Obfuscated Files or Information: Binary Padding — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 2 tracked threats
  • T1053.005 Scheduled Task — Persistenceobserved in 1 of 2 tracked threats
  • T1059.001 PowerShell — Executionobserved in 1 of 2 tracked threats
  • T1059.003 Windows Command Shell — Executionobserved in 1 of 2 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats

Tracked threats