Pollblend Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 17, 2025
Last Seen
July 28, 2026

Pollblend is a malware family highlighted in Frontline Intelligence analyses of UNC1549 TTPs and related tooling, with campaigns targeting the aerospace and defense ecosystem.

Overview

Pollblend is a malware family highlighted in Frontline Intelligence analyses of UNC1549 TTPs and related tooling, with campaigns targeting the aerospace and defense ecosystem. It is described as using custom tools within UNC1549-aligned operations to infiltrate and operate in high-value defense networks, signaling a notable risk to critical infrastructure sectors. The significance lies in its association with targeted, sector-specific campaigns and bespoke tooling that complicate detection and response.

Related Threat Clusters

Recent Intelligence Reports

  • Mirage Kitten targets Middle East and Africa region with new malware — Securelist · July 28, 2026
  • Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting ... — Cloud.Google · November 17, 2025
  • Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem — Mandiant · November 17, 2025

CVSS v3.1 Breakdown