UNC1549 Espionage Campaign Targets Aerospace and Defense Sectors
Article Content
Browse articles
Since mid-2024, the threat group UNC1549 has conducted targeted cyber campaigns against the aerospace, aviation, and defense industries, particularly focusing on entities in the Middle East. Mandiant has documented various tactics, techniques, and procedures (TTPs) used by this group, which is suspected to have links to Iran. The ongoing espionage activities aim to gain initial access to sensitive environments within these sectors.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (3)
Following this threat?
Track Unc1549, Deeproot and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by Kaspersky. The group, also known as Mirage Kitten, has been active since at least 2018, primarily…