Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC1549

Also known as: Nimbus Manticore

Description

UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.

AI Analysis

· 1 week ago

Executive Summary

UNC1549, also known as Nimbus Manticore, is an Iranian threat actor linked to Tortoiseshell and potentially to the IRGC. Active since at least June 2022, UNC1549 primarily targets Middle Eastern entities through sophisticated cyberattacks involving spear-phishing campaigns and custom malware deployment.

Goals & Targeting

UNC1549's primary motivation appears to align with Iranian geopolitical interests, likely targeting entities within the Middle East to gather intelligence or disrupt operations. Their focus on sectors in this region suggests a strategic alignment with potential IRGC activities.

Enhanced Description

UNC1549 is a state-sponsored Iranian threat group that has been operational since mid-2022. Known for their focus on the Middle East, they employ a variety of tactics including spear-phishing emails with malicious macros and credential harvesting to breach targets. Their toolset includes custom malware such as MINIBIKE and MINIBUS backdoors, demonstrating advanced capabilities in persistence and lateral movement. Additionally, UNC1549 has been observed using evasion techniques like LIGHTRAIL tunneler to maintain covert communication channels.

Key Capabilities

  • Spear-phishing with malicious macros
  • Custom malware deployment (MINIBIKE, MINIBUS)
  • Evasion techniques
  • Covert communication tunneler (LIGHTRAIL)

MITRE ATT&CK Tactics

Initial Access
Execution
Lateral Movement

ATT&CK Techniques

T1059
T1078.001
T1566.003

Software / Tooling

MINIBIKE
MINIBUS
LIGHTRAIL

Campaigns & Victims

UNC1549 has conducted numerous campaigns globally, with a particular emphasis on Middle Eastern targets. Their operations often start with spear-phishing emails and escalate using custom malware for persistence and data exfiltration.

IOC Patterns

  • Spear-phishing emails
  • Malicious Office documents with macros
  • Custom backdoor installations

Recommended Actions

  • Implement rigorous phishing detection solutions
  • Enhance monitoring for custom malware signatures
  • Conduct regular security audits of Middle Eastern assets

Suggested Tags

APT
Geopolitical Targeting
Iranian Cyber Threats

Confidence Assessment

Moderate confidence in the group's existence and activities, with clear technical details but gaps in primary motivation and exact operational timeline.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

4

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Backdoor / C2
APT
Geopolitical Targeting
Iranian Cyber Threats

Details

Type
Unknown
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.