Threat reportAPTTL-2026-0815

UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware

highACTIVE

UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle (TL-2026-0815), also tracked as Iranian Dream Job, is a high-severity advanced persistent threat campaign, first published 2026-06-16. It is attributed to UNC1549 (Iran) with high confidence, affects Aerospace & Defense Sector Aerospace, aviation and defense, maps to 31 MITRE ATT&CK techniques (T1003.006, T1005, T1018), and is covered by 9 detection rules and 42 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
31MITRE ATT&CK
Actors
1UNC1549
Detection rules
9SPL · KQL · Sigma
IOCs
42Indicators of compromise

Key facts for TL-2026-0815

Threat ID
TL-2026-0815
Also known as
Iranian Dream Job, Operation Nimbus Manticore
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
UNC1549
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
aerospace, aviation, defense, defense manufacturing, telecommunications, satellite communications
Target regions
Middle East, Israel, United Arab Emirates, Turkey, India, Albania, Western Europe, Portugal, Sweden, Denmark, France, United Kingdom
Detection rules
9
Indicators of compromise
42

Malware and tooling in UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle

Malware and tooling: DCSYNCER.SLICK, MINIBIKE, MiniBrowse, SIGHTGRAB, TRUSTRAP, ZeroTier, ngrok - S0508

How UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle works

UNC1549 is an Iran-nexus (IRGC-aligned) cyber-espionage group active since at least June 2022 that targets aerospace, aviation, defense and telecommunications organizations. It uses fake React-based career/recruitment portals and LinkedIn job lures impersonating Boeing, Airbus, Rheinmetall, Telespazio and Safran to deliver custom DLL-sideloaded malware (MINIBIKE/MiniJunk, MiniBrowse, SIGHTGRAB, TRUSTRAP and related backdoors) for persistence, credential theft, DCSync, and exfiltration over Azure-proxied C2. Operations expanded into Western Europe by September 2025.

UNC1549 (overlapping with Check Point's Nimbus Manticore, Microsoft's Smoke Sandstorm, Crowdstrike-tracked TA455, and PRODAFT's Subtle Snail) is a mature Iran-nexus espionage actor assessed to align with Islamic Revolutionary Guard Corps (IRGC) strategic priorities. First observed in June 2022 targeting Middle Eastern aerospace and defense entities, the group expanded through 2023-2025 to the global aerospace/defense supply chain and, by September 2025, to Western Europe (Portugal, Sweden, Denmark) and to telecommunications providers across Canada, France, the UAE, the UK and the United States.

Initial access relies on highly targeted social engineering: spear-phishing emails and fraudulent LinkedIn recruiter profiles drive victims to fake, React-based career portals that impersonate Boeing, Airbus, Rheinmetall, Teledyne FLIR, Telespazio and Safran. Victims are issued pre-shared credentials and download malicious ZIP archives (e.g. survey.zip) containing a legitimate, validly signed executable plus a malicious sideloaded DLL. UNC1549 also exploits trusted third-party relationships and VDI breakouts to reach primary targets.

The malware ecosystem centers on MINIBIKE (evolved into MiniJunk/SlugResin), a heavily obfuscated HTTPS backdoor supporting ~12 commands for reconnaissance, file operations, process creation via named pipes, and DLL loading. Supporting tools include MiniBrowse (Chrome/Edge/Brave credential and clipboard stealer), SIGHTGRAB (periodic screenshot capture written to C:\Users\Public\Videos and \Music), TRUSTRAP (fake credential-prompt windows), DCSYNCER.SLICK (DCSync via MS-DRSR), CRASHPAD, LIGHTRAIL, DEEPROOT, TWOSTROKE, GHOSTLINE, POLLBLEND, and SCCMVNC, with ZeroTier and ngrok used for tunneling.

Tradecraft emphasizes operational security: LLVM compiler-level obfuscation with opaque predicates and control-flow flattening, per-string XOR encryption, binary-size inflation with junk code to defeat AV size limits, masquerading as legitimate Microsoft/VMware/Citrix/FortiGate/NVIDIA binaries via DLL side-loading, valid code-signing certificates purchased through SSL.com (from May 2025) masquerading as European IT firms, RDP history deletion, and reverse SSH tunnels (ssh.exe -R over port 443). Command and control is proxied almost entirely through Microsoft Azure App Service (*.azurewebsites.net) and Azure Cloud App (*.cloudapp.azure.com) domains plus VPSes, blending malicious traffic into trusted cloud infrastructure. Credential access includes DCSync, browser credential theft, Kerberoasting (obfuscated Invoke-Kerberoast), and password spraying; lateral movement uses RDP session hijacking (tscon/query session) and SCCMVNC. No CVE is associated with this campaign; the threat is TTP- and tooling-driven rather than vulnerability-driven.

MITRE ATT&CK techniques used in TL-2026-0815

Credential Access

T1003.006 OS Credential Dumping: DCSync; T1110.003 Brute Force: Password Spraying; T1555.003 Credentials from Password Stores: Credentials from Web Browsers; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting

Collection

T1005 Data from Local System; T1113 Screen Capture; T1213.002 Data from Information Repositories: SharePoint

Discovery

T1018 Remote System Discovery; T1087.002 Account Discovery: Domain Account

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1027.001 Obfuscated Files or Information: Binary Padding; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.001 User Execution: Malicious Link

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1132 Data Encoding; T1572 Protocol Tunneling

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship; T1566.001 Phishing: Spearphishing Attachment; T1566.002 Phishing: Spearphishing Link

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing; T1685.005 Clear Windows Event Logs

stealth

T1574.001 DLL

Affected products and versions in UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle

  • Aerospace & Defense Sector — Aerospace, aviation and defense manufacturers and their third-party suppliers
    Vulnerable versions: organizations targeted via spear-phishing, fake recruitment portals, and trusted-relationship access
  • Telecommunications Sector — Telecom and satellite providers (11 firms, 34 devices compromised)
    Vulnerable versions: personnel targeted via LinkedIn job lures and MINIBIKE/SlugResin DLL side-loading
  • Microsoft — Azure App Service / Azure Cloud Apps (abused as C2 hosting, not a product vulnerability)
    Vulnerable versions: *.azurewebsites.net; *.cloudapp.azure.com used for malicious C2 proxying

Remediation for UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle

Immediate actions

  • Block and alert on all listed Azure App Service (*.azurewebsites.net) and Azure Cloud App (*.cloudapp.azure.com) C2 domains and the SSH-tunneling IPs (104.194.215.88, 13.60.50.172, 167.172.137.208, 34.18.42.26, 4.188.75.206, 4.240.113.27, 40.119.176.233) at the perimeter and proxy
  • Hunt for unexpected outbound ssh.exe processes using -R reverse-tunnel flags, especially over port 443
  • Quarantine and triage hosts matching MINIBIKE/MiniJunk/MiniBrowse/LIGHTRAIL hashes; reset credentials for any user who interacted with the fake recruitment portals
  • Alert on DCSync-style MS-DRSR replication (GetNCChanges) from non-domain-controller hosts

Workarounds

  • Restrict execution of openssh ssh.exe where not operationally required
  • Disable or tightly monitor SharePoint mass-download and information-repository access
  • Filter newly-registered and lookalike recruitment domains impersonating aerospace/defense brands

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading against signed Microsoft/VMware/Citrix/FortiGate/NVIDIA binaries
  • Enforce phishing-resistant MFA and conditional access to neutralize stolen browser/VPN credentials
  • Implement application allow-listing and monitor scheduled-task and Run-key persistence creation
  • Segment and monitor third-party/supplier access and VDI environments to break trusted-relationship abuse

Timeline of UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle

  • UNC1549 operations first observed targeting aerospace and defense organizations in the Middle East (Israel, UAE).
  • Campaign expands across the global aerospace and defense supply chain, increasingly leveraging trusted third-party access and VDI breakouts.
  • Group begins purchasing valid code-signing certificates through SSL.com, masquerading as European IT organizations to sign malware.
  • PRODAFT/Mandiant report 34 devices compromised across 11 telecom firms in Canada, France, UAE, UK and US via LinkedIn job lures and MINIBIKE/SlugResin.
  • Check Point publishes Nimbus Manticore research documenting new malware (MiniJunk, MiniBrowse) targeting defense, telecom and aviation in Portugal, Sweden and Denmark.
  • Cloud Security Alliance research note assesses Nimbus Manticore as IRGC-aligned, deploying AI-assisted backdoors against Western sectors.
  • Google Cloud/Mandiant Frontline Intelligence details full UNC1549 toolset (MINIBIKE, TWOSTROKE, DEEPROOT, LIGHTRAIL, GHOSTLINE, POLLBLEND, DCSYNCER.SLICK) and Azure C2 infrastructure.
  • Picus Security publishes consolidated UNC1549 TTP analysis (Threat ID 74718); threat documented and operationalized for detection in the Threadlinqs platform.

Sources cited for UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle

Detection coverage for TL-2026-0815

As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0815 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
42 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats