UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware — Threadlinqs Intelligence
As of 2026-06-16, UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware is a high-severity apt threat attributed to UNC1549 (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-0815 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: UNC1549 · Iran · ESPIONAGE
UNC1549 is an Iran-nexus (IRGC-aligned) cyber-espionage group active since at least June 2022 that targets aerospace, aviation, defense and telecommunications organizations. It uses fake React-based
UNC1549 (overlapping with Check Point's Nimbus Manticore, Microsoft's Smoke Sandstorm, Crowdstrike-tracked TA455, and PRODAFT's Subtle Snail) is a mature Iran-nexus espionage actor assessed to align with Islamic Revolutionary Guard Corps (IRGC) strategic priorities. First observed in June 2022 targeting Middle Eastern aerospace and defense entities, the group expanded through 2023-2025 to the global aerospace/defense supply chain and, by September 2025, to Western Europe (Portugal, Sweden, Denmark) and to telecommunications providers across Canada, France, the UAE, the UK and the United States.
Initial access relies on highly targeted social engineering: spear-phishing emails and fraudulent LinkedIn recruiter profiles drive victims to fake, React-based career portals that impersonate Boeing, Airbus, Rheinmetall, Teledyne FLIR, Telespazio and Safran. Victims are issued pre-shared credentials and download malicious ZIP archives (e.g. survey.zip) containing a legitimate, validly signed executable plus a malicious sideloaded DLL. UNC1549 also exploits trusted third-party relationships and VDI breakouts to reach primary targets.
The malware ecosystem centers on MINIBIKE (evolved into MiniJunk/SlugResin), a heavily obfuscated HTTPS backdoor supporting ~12 commands for reconnaissance, file operations, process creation via named pipes, and DLL loading. Supporting tools include MiniBrowse (Chrome/Edge/Brave credential and clipboard stealer), SIGHTGRAB (periodic screenshot capture written to C:\Users\Public\Videos and \Music), TRUSTRAP (fake credential-prompt windows), DCSYNCER.SLICK (DCSync via MS-DRSR), CRASHPAD, LIGHTRAIL, DEEPROOT, TWOSTROKE, GHOSTLINE, POLLBLEND, and SCCMVNC, with ZeroTier and ngrok used for tunneling.
Tradecraft emphasizes operational security: LLVM compiler-level obfuscation with opaque predicates and control-flow flattening, per-string XOR encryption, binary-size inflation with junk code to defeat AV size limits, masquerading as legitimate Microsoft/VMware/Citrix/FortiGate/NVIDIA binaries via DLL side-loading, valid code-signing certificates purchased through SSL.com (from May 2025) masquerading as European IT firms, RDP history deletion, and reverse SSH tunnels (ssh.exe -R over port 443). Command and control is proxied almost entirely through Microsoft Azure App Service (*.azurewebsites.net) and Azure Cloud App (*.cloudapp.azure.com) domains plus VPSes, blending malicious traffic into trusted cloud infrastructure. Credential access includes DCSync, browser credential theft, Kerberoasting (obfuscated Invoke-Kerberoast), and password spraying; lateral movement uses RDP session hijacking (tscon/query session) and SCCMVNC. No CVE is associated with this campaign; the threat is TTP- and tooling-driven rather than vulnerability-driven.
Target sectors: aerospace, aviation, defense, defense manufacturing, telecommunications, satellite communications
Target regions: Middle East, Israel, United Arab Emirates, Turkey, India, Albania, Western Europe, Portugal, Sweden, Denmark, France, United Kingdom
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1566.002, T1566.001, T1199, T1078, T1059.001, T1059.003, T1204.001, T1053.005, T1547.001, T1574.001