UNC1549 Critical Infrastructure Espionage Attack
Since mid-2024, UNC1549 has been executing highly targeted espionage campaigns against organizations in the aerospace, aviation, and defense sectors. The group gains initial access through tailored spear-phishing aimed at credential theft and malware delivery, as well as by compromising trusted third-party access and supply-chain relationships to pivot into downstream environments. The threat actor has previously leveraged CVE-2021-26855 and CVE-2020-0688 in past campaigns to gain initial access and facilitate follow-on exploitation. UNC1549 employs multiple custom malware families and covert operational techniques to establish persistence and evade detection: - MINIBIKE: Modular backdoor enabling credential theft, keylogging, screenshot capture, and deployment of additional payloads. - TWOSTROKE: Remote access tool designed for persistence and full host control. - DEEPROOT: Linux-focused variant providing similar capabilities across non-Windows platforms. - LIGHTRAIL & GHOSTLINE: Covert C2 and tunneling tools that disguise malicious traffic within legitimate cloud services to support resilient communications and data exfiltration. These operations are consistent with state- intelligence requirements, emphasizing the theft of sensitive technical data, monitoring of high-value communications, and maintaining long-term strategic footholds inside targeted environments.
Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.
Fortinet customers are protected through the FortiGuard Intrusion Prevention System (IPS) Security Service, which detects and blocks exploit attempts targeting known vulnerabilities associated with this activity. In addition, FortiGuard provides coverage against malware leveraged throughout the campaign. For the complete list of available protections, please refer to the Solution tab.
November 27, 2025: FortiGuard released a Threat Signal Report on UNC1549 Critical Infrastructure Espionage Attack.
November 17, 2025: Google Released Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem.
February 27, 2024: Mandiant released a blog post suspected Iran-nexus espionage activity targeting the aerospace, aviation and defense industries in Middle East countries, including Israel and the United Arab Emirates (UAE) and potentially Turkey, India, and Albania.
March 12, 2021: FortiGuard Labs released an Outbreak Alert for Microsoft Exchange Server remote code execution (RCE) vulnerabilities. These same vulnerabilities have previously been exploited by UNC1549 to gain initial access into target networks, highlighting the ongoing risk posed by unpatched or misconfigured Exchange servers.
Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.
Assisted Response Services
Vulnerability Management
Attack Surface Hardening
Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.
Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.
Sources of information in support and relation to this Outbreak and vendor.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
