Also known as: Smoke Sandstorm, UNC1549, Iranian Dream Job, tracked as, 2023, which between February, HIUPAN, EggStreme Agent, Ferocious Kitten, defense companies, APT33, APT28, Fancy Bear, UNC1151, 560048, IMPERIAL KITTEN, Yellow Liderc, Imperial Kitten, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, Agrius, Pensive Ursa, Gorem RAT, Storm-0257, DEV-0228
Screening Serpens is an advanced threat actor with Iranian ties that has operated since at least 2022 and now attacks a broad portfolio of governments, defense contractors and critical infrastructure providers across the U.S., Israel, UAE and Europe. The group’s campaign strategies are heavily centered on social engineering, deploying spearphishing emails that masquerade as legitimate hiring platforms or job‑offer lures to entice target personnel into executing malicious download links or attachments. Once a foothold is achieved, Screening Serpens deploys sophisticated Remote Access Trojan families – MiniUpdate and MiniJunk V2 – that exploit .NET runtime configuration files, AppDomainManager hijacking and DLL side-loading techniques. These trojans also make extensive use of scheduled tasks and system boot‑or‑logon autostart mechanisms for persistence while employing obfuscated code, junk padding and privilege bypass methods to evade detection. The group consistently hosts its command‑and‑control infrastructure in cloud services (e.g., Azure) and has demonstrated the ability to adapt its delivery mechanisms, including USB-based payloads via HIUPAN/USBFect. Operationally resilient, Screening Serpens maintains persistent access over extended periods while routinely cleansing artifacts. Its tactics reflect a blend of espionage and potential financial gain objectives, with known credential harvesting activities aimed at extracting sensitive data from high‑profile industry sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Screening Serpens, an Iran-linked APT also known as Smoke Sandstorm or UNC1549, has expanded beyond its Middle Eastern roots to target high‑value sectors such as aerospace, defense manufacturing and telecommunications in the U.S., Israel and European markets. The group employs highly tailored social engineering recruitment lures combined with persistent remote access trojans (MiniUpdate/MiniJunk V2) that leverage DLL sideloading, .NET runtime manipulation and cloud‑based C2 to maintain long‑term espionage capabilities.
Goals & Targeting
The actor’s strategic objectives revolve around long‑term intelligence gathering on defense, aerospace, telecommunications, and energy sectors worldwide, particularly in technologically advanced organizations. While the primary stated motive is financial gain, evidence of espionage—such as credential theft, system checks for software discovery, and extensive persistence mechanisms—suggests that securing intellectual property and sensitive operational data remains paramount. The targeting profile favors professionals with privileged access or roles tied to procurement, logistics, or manufacturing processes, making them ideal entry points through job‑offer social engineering.
Enhanced Description
No campaigns linked yet.
No observed data linked yet.
40
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics