Also known as: Nimbus Manticore
UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.
Executive Summary
UNC1549, also known as Nimbus Manticore, is an Iranian threat actor linked to Tortoiseshell and potentially to the IRGC. Active since at least June 2022, UNC1549 primarily targets Middle Eastern entities through sophisticated cyberattacks involving spear-phishing campaigns and custom malware deployment.
Goals & Targeting
UNC1549's primary motivation appears to align with Iranian geopolitical interests, likely targeting entities within the Middle East to gather intelligence or disrupt operations. Their focus on sectors in this region suggests a strategic alignment with potential IRGC activities.
Enhanced Description
UNC1549 is a state-sponsored Iranian threat group that has been operational since mid-2022. Known for their focus on the Middle East, they employ a variety of tactics including spear-phishing emails with malicious macros and credential harvesting to breach targets. Their toolset includes custom malware such as MINIBIKE and MINIBUS backdoors, demonstrating advanced capabilities in persistence and lateral movement. Additionally, UNC1549 has been observed using evasion techniques like LIGHTRAIL tunneler to maintain covert communication channels.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC1549 has conducted numerous campaigns globally, with a particular emphasis on Middle Eastern targets. Their operations often start with spear-phishing emails and escalate using custom malware for persistence and data exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the group's existence and activities, with clear technical details but gaps in primary motivation and exact operational timeline.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
4
IOCs
0
Observed Data
0
Tactics