Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors screening serpens

Also known as: Smoke Sandstorm, UNC1549, Iranian Dream Job, tracked as, 2023, which between February, HIUPAN, EggStreme Agent, Ferocious Kitten, defense companies, APT33, APT28, Fancy Bear, UNC1151, 560048, IMPERIAL KITTEN, Yellow Liderc, Imperial Kitten, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, Agrius, Pensive Ursa, Gorem RAT, Storm-0257, DEV-0228

Description

Screening Serpens is an advanced threat actor with Iranian ties that has operated since at least 2022 and now attacks a broad portfolio of governments, defense contractors and critical infrastructure providers across the U.S., Israel, UAE and Europe. The group’s campaign strategies are heavily centered on social engineering, deploying spearphishing emails that masquerade as legitimate hiring platforms or job‑offer lures to entice target personnel into executing malicious download links or attachments. Once a foothold is achieved, Screening Serpens deploys sophisticated Remote Access Trojan families – MiniUpdate and MiniJunk V2 – that exploit .NET runtime configuration files, AppDomainManager hijacking and DLL side-loading techniques. These trojans also make extensive use of scheduled tasks and system boot‑or‑logon autostart mechanisms for persistence while employing obfuscated code, junk padding and privilege bypass methods to evade detection. The group consistently hosts its command‑and‑control infrastructure in cloud services (e.g., Azure) and has demonstrated the ability to adapt its delivery mechanisms, including USB-based payloads via HIUPAN/USBFect. Operationally resilient, Screening Serpens maintains persistent access over extended periods while routinely cleansing artifacts. Its tactics reflect a blend of espionage and potential financial gain objectives, with known credential harvesting activities aimed at extracting sensitive data from high‑profile industry sectors.

Goals & Targeting

Targeted Sectors

Aerospace
Defense
Communications
Government
Financial services
Manufacturing
Telecommunications
Information technology
Construction
Energy
Healthcare
Aviation
Critical infrastructure
Education
Media
Non profit
Utilities
Transportation
Oil gas
Maritime
Retail
Pharmaceutical
Legal services

Targeted Countries / Regions

United States of America
Israel
United Arab Emirates
AE
IR
US
IL
CN
IN
JP
UA
TR
BY
KP
KZ
VN
EG
SG
FR
BR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 13 hours ago

Executive Summary

Screening Serpens, an Iran-linked APT also known as Smoke Sandstorm or UNC1549, has expanded beyond its Middle Eastern roots to target high‑value sectors such as aerospace, defense manufacturing and telecommunications in the U.S., Israel and European markets. The group employs highly tailored social engineering recruitment lures combined with persistent remote access trojans (MiniUpdate/MiniJunk V2) that leverage DLL sideloading, .NET runtime manipulation and cloud‑based C2 to maintain long‑term espionage capabilities.

Goals & Targeting

The actor’s strategic objectives revolve around long‑term intelligence gathering on defense, aerospace, telecommunications, and energy sectors worldwide, particularly in technologically advanced organizations. While the primary stated motive is financial gain, evidence of espionage—such as credential theft, system checks for software discovery, and extensive persistence mechanisms—suggests that securing intellectual property and sensitive operational data remains paramount. The targeting profile favors professionals with privileged access or roles tied to procurement, logistics, or manufacturing processes, making them ideal entry points through job‑offer social engineering.

Enhanced Description

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 1 Filename 5 Domain 14

References

  1. unit42.paloaltonetworks.com — Cited by web research for: HIUPAN
  2. www.sentinelone.com — Cited by web research for: Ferocious Kitten
  3. www.paloaltonetworks.com — Cited by web research for: defense companies
  4. www.cyfirma.com — Cited by web research for: UNC1151
  5. unit42.paloaltonetworks.com — Cited by web research for: Payload
  6. gurucul.com — Cited by web research for: Utilities

Intel Summary

40

Techniques

45

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

APT
Backdoor / C2
Espionage
Cyber Espionage
Sectors: Aerospace, Defense, Communications
Cloud Infrastructure

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.