UNC1549
Aliases: Nimbus Manticore
- First seen
- 2022-06-01 00:00:00
- Origin
- IR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:14:26
Targeted industries: defense-and-aerospace government-and-public-sector healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:sa country_code:ae country_code:iq
Context
UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.
Reports & references
- Mandiant — Suspected Iranian Unc1549 Targets Israel Middle East (report)
- research.checkpoint.com — Nimbus Manticore Deploys New Malware Targeting Europe (report)
- blog.checkpoint.com — Iranian Threat Actor Nimbus Manticore Expands Campaigns Into Europe With Advanced Malware And Fake Job Lures (report)