UNC1549

Aliases: Nimbus Manticore

First seen
2022-06-01 00:00:00
Origin
IR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:14:26

Targeted industries: defense-and-aerospace government-and-public-sector healthcare-and-pharmaceutical financial-services

Targeted regions: country_code:sa country_code:ae country_code:iq

Context

UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.

Reports & references

  • Mandiant — Suspected Iranian Unc1549 Targets Israel Middle East (report)
  • research.checkpoint.com — Nimbus Manticore Deploys New Malware Targeting Europe (report)
  • blog.checkpoint.com — Iranian Threat Actor Nimbus Manticore Expands Campaigns Into Europe With Advanced Malware And Fake Job Lures (report)

External references