# UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware

> UNC1549 is an Iran-nexus (IRGC-aligned) cyber-espionage group active since at least June 2022 that targets aerospace, aviation, defense and telecommunications organizations. It uses fake React-based career/recruitment portals and LinkedIn job lures impersonating Boeing, Airbus, Rheinmetall, Telespazio and Safran to deliver custom DLL-sideloaded malware (MINIBIKE/MiniJunk, MiniBrowse, SIGHTGRAB, TRUSTRAP and related backdoors) for persistence, credential theft, DCSync, and exfiltration over Azure-proxied C2. Operations expanded into Western Europe by September 2025.

- **Published:** 2026-06-16T00:00:00Z
- **Last reviewed:** 2026-06-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0815
- **ID:** TL-2026-0815
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** UNC1549 (Iran)
- **Detections:** 9 · **IOCs:** 42 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UNC1549 (overlapping with Check Point's Nimbus Manticore, Microsoft's Smoke Sandstorm, Crowdstrike-tracked TA455, and PRODAFT's Subtle Snail) is a mature Iran-nexus espionage actor assessed to align with Islamic Revolutionary Guard Corps (IRGC) strategic priorities. First observed in June 2022 targeting Middle Eastern aerospace and defense entities, the group expanded through 2023-2025 to the global aerospace/defense supply chain and, by September 2025, to Western Europe (Portugal, Sweden, Denmark) and to telecommunications providers across Canada, France, the UAE, the UK and the United States.

Initial access relies on highly targeted social engineering: spear-phishing emails and fraudulent LinkedIn recruiter profiles drive victims to fake, React-based career portals that impersonate Boeing, Airbus, Rheinmetall, Teledyne FLIR, Telespazio and Safran. Victims are issued pre-shared credentials and download malicious ZIP archives (e.g. survey.zip) containing a legitimate, validly signed executable plus a malicious sideloaded DLL. UNC1549 also exploits trusted third-party relationships and VDI breakouts to reach primary targets.

The malware ecosystem centers on MINIBIKE (evolved into MiniJunk/SlugResin), a heavily obfuscated HTTPS backdoor supporting ~12 commands for reconnaissance, file operations, process creation via named pipes, and DLL loading. Supporting tools include MiniBrowse (Chrome/Edge/Brave credential and clipboard stealer), SIGHTGRAB (periodic screenshot capture written to C:\Users\Public\Videos and \Music), TRUSTRAP (fake credential-prompt windows), DCSYNCER.SLICK (DCSync via MS-DRSR), CRASHPAD, LIGHTRAIL, DEEPROOT, TWOSTROKE, GHOSTLINE, POLLBLEND, and SCCMVNC, with ZeroTier and ngrok used for tunneling.

Tradecraft emphasizes operational security: LLVM compiler-level obfuscation with opaque predicates and control-flow flattening, per-string XOR encryption, binary-size inflation with junk code to defeat AV size limits, masquerading as legitimate Microsoft/VMware/Citrix/FortiGate/NVIDIA binaries via DLL side-loading, valid code-signing certificates purchased through SSL.com (from May 2025) masquerading as European IT firms, RDP history deletion, and reverse SSH tunnels (ssh.exe -R over port 443). Command and control is proxied almost entirely through Microsoft Azure App Service (*.azurewebsites.net) and Azure Cloud App (*.cloudapp.azure.com) domains plus VPSes, blending malicious traffic into trusted cloud infrastructure. Credential access includes DCSync, browser credential theft, Kerberoasting (obfuscated Invoke-Kerberoast), and password spraying; lateral movement uses RDP session hijacking (tscon/query session) and SCCMVNC. No CVE is associated with this campaign; the threat is TTP- and tooling-driven rather than vulnerability-driven.

## MITRE ATT&CK

- T1566.002 Phishing: Spearphishing Link
- T1566.001 Phishing: Spearphishing Attachment
- T1199 Trusted Relationship
- T1078 Valid Accounts
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1204.001 User Execution: Malicious Link
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1574.001 DLL
- T1574.001 DLL
- T1027 Obfuscated Files or Information
- T1027.001 Obfuscated Files or Information: Binary Padding
- T1036 Masquerading
- T1685.005 Clear Windows Event Logs
- T1140 Deobfuscate/Decode Files or Information
- T1553.002 Subvert Trust Controls: Code Signing
- T1003.006 OS Credential Dumping: DCSync
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1110.003 Brute Force: Password Spraying
- T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
- T1087.002 Account Discovery: Domain Account
- T1018 Remote System Discovery
- T1021.001 Remote Services: Remote Desktop Protocol
- T1113 Screen Capture
- T1213.002 Data from Information Repositories: SharePoint
- T1005 Data from Local System
- T1572 Protocol Tunneling
- T1071.001 Application Layer Protocol: Web Protocols
- T1090 Proxy
- T1132 Data Encoding
- T1041 Exfiltration Over C2 Channel

## Sources

- [Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem](https://cloud.google.com/blog/topics/threat-intelligence/analysis-of-unc1549-ttps-targeting-aerospace-defense)
- [Nimbus Manticore Deploys New Malware Targeting Europe](https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/)
- [UNC1549 TTPs: Iranian APT Targeting Aerospace and Defense](https://www.picussecurity.com/resource/blog/unc1549-ttps-iranian-apt-targeting-aerospace-and-defense)
- [UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware](https://thehackernews.com/2025/09/unc1549-hacks-34-devices-in-11-telecom.html)
- [CSA Research Note: Nimbus Manticore - AI-Assisted Backdoors Target Western Sectors (IRGC)](https://labs.cloudsecurityalliance.org/research/csa-research-note-nimbus-manticore-ai-assisted-malware-irgc/)
- [Check Point tracks Nimbus Manticore Iranian APT targeting critical infrastructure in Europe, Middle East](https://industrialcyber.co/threats-attacks/check-point-tracks-nimbus-manticore-iranian-apt-targeting-critical-infrastructure-in-europe-middle-east/)
- [Iran-Linked Hackers Target Europe With New Malware](https://www.darkreading.com/cyberattacks-data-breaches/iran-linked-hackers-europe-new-malware)
- [Mandiant tracks surge in UNC1549 campaigns, hitting aerospace and defense through third-party access](https://industrialcyber.co/ransomware/mandiant-tracks-surge-in-unc1549-campaigns-hitting-aerospace-and-defense-through-third-party-access/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0815
