UNC1549 is an Advanced Persistent Threat (APT) group implicated in state-like cyber espionage campaigns targeting critical infrastructure and high-value sectors such as aerospace and defense.
Overview
UNC1549 is an Advanced Persistent Threat (APT) group implicated in state-like cyber espionage campaigns targeting critical infrastructure and high-value sectors such as aerospace and defense. The group is characterized by bespoke, custom-developed tools and malware, with a focus on credential Theft and long-term footholds in target networks. Its activity underscores a deliberate effort to harvest sensitive access within strategically important industries.
Related Threat Clusters
-
Iranian Hackers Target US Aviation with New Malware and SEO Poisoning
Iranian state-aligned hackers, known as Nimbus Manticore (UNC1549), have intensified cyberattacks against the US aviation sector amid the ongoing US-Iran military conflict. Utilizing career-themed phishing and a novel…
6 articles · Updated May 26, 2026 -
Tortoiseshell Expands Malware Arsenal with New Backdoor and SSH Tunneling Tool
The Iranian-linked Tortoiseshell APT group has expanded its malware toolkit, introducing a new backdoor and reverse SSH tunneling utility. Group-IB Threat Intelligence identified these developments following a report by…
6 articles · Updated August 26, 2026 -
Mirage Kitten Malware Targets Middle East and Africa with New Toolset
The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as…
2 articles · Updated July 30, 2026 -
Iran-linked Screening Serpens Group Deploys MiniUpdate RAT via Azure C2
The Screening Serpens group, linked to Iran, has initiated a targeted espionage campaign using a new remote access Trojan (RAT) named MiniUpdate. This campaign primarily targets technology professionals in the United…
2 articles · Updated May 25, 2026 -
Nimbus Manticore APT Targets Aerospace Sector with Fake Job Schemes
The Iranian-aligned threat group Nimbus Manticore has launched a cyber campaign targeting aerospace and defense organizations. This operation utilizes a fake recruitment portal to distribute custom malware via a…
2 articles · Updated June 2, 2026 -
UAE Thwarts Major Cyberattacks on Key Sectors
On August 10, 2026, the UAE Cybersecurity Council announced that it successfully thwarted advanced, coordinated cyberattacks targeting the aviation, energy, and education sectors. The attacks were detected and contained…
18 articles · Updated August 10, 2026 -
Iran's Cyber Response to U.S. Military Strikes Expected Amid Rising Tensions
Following U.S. military strikes on Iran, there is an anticipated increase in cyber warfare activities targeting U.S. operational technology and critical infrastructure. Iran is expected to retaliate with cyber attacks…
767 articles · Updated February 28, 2026 -
Critical RCE Vulnerability in Imunify360 Exposes Millions of Linux Servers
A remote code execution vulnerability in the Imunify360 antivirus system affects millions of Linux servers, allowing attackers to upload malicious files and execute arbitrary code. This flaw impacts versions prior to…
1 article · Updated November 18, 2025 -
Amazon Reports Rise in Cyber-Enabled Kinetic Targeting by Nation-States
Amazon's Threat Intelligence team has identified a trend where nation-state actors utilize cyber operations to facilitate physical military strikes, termed 'cyber-enabled kinetic targeting.' This new operational model…
6 articles · Updated November 19, 2025 -
UNC1549 Espionage Campaign Targets Aerospace and Defense Sectors
Since mid-2024, the threat group UNC1549 has conducted targeted cyber campaigns against the aerospace, aviation, and defense industries, particularly focusing on entities in the Middle East. Mandiant has documented…
3 articles · Updated November 17, 2025
Recent Intelligence Reports
- Iran — Cybersecuritynews · August 26, 2026
- Securelist — securelist.com · August 26, 2026
- Tortoiseshell: New Toolset and Operational Infrastructure Exposed | Group — Group-Ib · August 26, 2026
- UAE Fends Off Third Sector-Targeting Cyberattack of 2026; Finance First, Now Aviation, Energy — Techtimes · August 10, 2026
- Cybersecurity Researchers Uncover Mirage Kitten Malware Sweeping Across Africa — Streamlinefeed.Co.Ke · July 30, 2026
- Mirage Kitten targets Middle East and Africa region with new malware — Securelist · July 28, 2026
- Nimbus Manticore APT Abuses Fake Recruitment Portal to Deliver Custom Malware — Cybersecuritynews · June 2, 2026
- Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware — Gbhackers · June 2, 2026