Activity timeline
TA455 appears in 2 tracked threats between and .
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
- T1090 Proxy — Command and Controlobserved in 2 of 2 tracked threats
- T1003.006 OS Credential Dumping: DCSync — Credential Accessobserved in 1 of 2 tracked threats
- T1005 Data from Local System — Collectionobserved in 1 of 2 tracked threats
- T1018 Remote System Discovery — Discoveryobserved in 1 of 2 tracked threats
- T1021 Remote Services — Lateral Movementobserved in 1 of 2 tracked threats
- T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 1 of 2 tracked threats
- T1027.001 Obfuscated Files or Information: Binary Padding — Stealth (formerly Defense Evasion)observed in 1 of 2 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 1 of 2 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 1 of 2 tracked threats
- T1059.001 PowerShell — Executionobserved in 1 of 2 tracked threats
- T1059.003 Windows Command Shell — Executionobserved in 1 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 1 of 2 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
Tracked threats
- UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom MalwareHIGH
- Iranian "Dream Job" Campaign (TA455 / Charming Kitten) — SnailResin Loader & SlugResin Backdoor Targeting Aerospace, Aviation & DefenseHIGH