UNC1549 is an Iranian-linked threat actor known for spear-phishing and custom backdoors targeting entities in the Middle East.
Analyst brief
UNC1549, also known as Nimbus Manticore, is an Iranian-linked threat actor potentially tied to the IRGC. It primarily targets entities worldwide, with a focus on the Middle East. The actor uses spear-phishing and credential harvesting for initial access, deploys custom backdoors like MINIBIKE and MINIBUS, and leverages the LIGHTRAIL tunneler with evasion techniques. Defenders should monitor for suspicious spear-phishing emails, anomalous credential usage, and abnormal tunneling traffic indicative of LIGHTRAIL activity.
UNC1549
Nimbus Manticore
unknown
UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.