Skip to content

Incidents attributed to:

UNC1549

UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC.

UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.

Also known as

Nimbus Manticore.

References


Actor metadata imported from Malpedia (Fraunhofer FKIE).