Unc1549 — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
23
occurrences
First Seen
November 17, 2025
Last Seen
August 26, 2026

UNC1549 is an Advanced Persistent Threat (APT) group implicated in state-like cyber espionage campaigns targeting critical infrastructure and high-value sectors such as aerospace and defense.

Overview

UNC1549 is an Advanced Persistent Threat (APT) group implicated in state-like cyber espionage campaigns targeting critical infrastructure and high-value sectors such as aerospace and defense. The group is characterized by bespoke, custom-developed tools and malware, with a focus on credential Theft and long-term footholds in target networks. Its activity underscores a deliberate effort to harvest sensitive access within strategically important industries.

Related Threat Clusters

Recent Intelligence Reports

  • Iran — Cybersecuritynews · August 26, 2026
  • Securelist — securelist.com · August 26, 2026
  • Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group — Group-Ib · August 26, 2026
  • UAE Fends Off Third Sector-Targeting Cyberattack of 2026; Finance First, Now Aviation, Energy — Techtimes · August 10, 2026
  • Cybersecurity Researchers Uncover Mirage Kitten Malware Sweeping Across Africa — Streamlinefeed.Co.Ke · July 30, 2026
  • Mirage Kitten targets Middle East and Africa region with new malware — Securelist · July 28, 2026
  • Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware — Cybersecuritynews · June 2, 2026
  • Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware — Gbhackers · June 2, 2026

CVSS v3.1 Breakdown