Activity timeline
UNC1549 appears in 6 tracked threats between and ; the busiest month was 2026-06 with 3 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 6 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 5 of 6 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 5 of 6 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 6 tracked threats
- T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 5 of 6 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 6 tracked threats
- T1053.005 Scheduled Task — Persistenceobserved in 4 of 6 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 4 of 6 tracked threats
- T1204.002 User Execution: Malicious File — Executionobserved in 4 of 6 tracked threats
- T1566.002 Spearphishing Link — Initial Accessobserved in 4 of 6 tracked threats
- T1583.006 Acquire Infrastructure: Web Services — Resource Developmentobserved in 4 of 6 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 6 tracked threats
- T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 6 tracked threats
- T1057 Process Discovery — Discoveryobserved in 3 of 6 tracked threats
- T1090 Proxy — Command and Controlobserved in 3 of 6 tracked threats
Tracked threats
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom MalwareHIGH
- Iranian "Dream Job" Campaign (TA455 / Charming Kitten) — SnailResin Loader & SlugResin Backdoor Targeting Aerospace, Aviation & DefenseHIGH
- Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll ImplantHIGH
- Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via AppDomain Hijacking — Operation Epic Fury Wave 3HIGH
- Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via AppDomainManager HijackingHIGH