Smoke Sandstorm, also known as Bohrium and TA455, is an Iranian state-aligned cyber espionage actor. The group has been linked to activity aligned with the Islamic Revolutionary Guard Corps and is associated with long-running credential theft and social-engineering operations, particularly against aerospace and defense-related targets. Reporting also notes overlap or close association in some vendor tracking with UNC1549 and Tortoiseshell-related activity, though such naming convergence is not uniformly resolved across vendors. The actor is known for highly targeted impersonation campaigns, including posing as recruiters on professional networking platforms to approach aerospace professionals with fake job opportunities. These operations are used to build trust, deliver malware, and steal credentials. Smoke Sandstorm has also been associated with infrastructure used in broader intrusion activity against strategically significant organizations in the Middle East. Observed tradecraft includes spearphishing and other social-engineering methods for initial access, credential harvesting through fake login portals, use of stolen credentials to access victim environments, and sustained post-compromise operations. The group has been tied to malware and tooling used for persistence, credential theft, remote access, and command execution, as well as web-based intrusion support infrastructure. Its operations are consistent with intelligence collection and long-term access rather than financially motivated crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UNC1549 (Nimbus Manticore) is an Iranian cyber-espionage group targeting aerospace, aviation, and defense sectors.
UNC1549 is an Iranian state-sponsored threat actor known for targeting aerospace, aviation, and defense industries in the Middle East. The group has evolved its operations by deploying multiple custom malware variants and advanced post-exploitation techniques to maintain persistence and evade detection.
UNC1549 is conducting espionage campaigns targeting aerospace, aviation, and defense organizations, as well as expanding to technology, hospitality, finance, and transportation sectors. The group uses spear-phishing, supply chain attacks, and custom malware to steal sensitive information, intellectual property, and credentials, primarily for strategic intelligence gathering aligned with Iranian interests.
UNC1549 is an Iranian cyber espionage group linked to Charming Kitten APT, known for using code-signing certificates from SSL.com to sign malware, making it harder to detect. They have targeted European organizations with backdoors and infostealers, leveraging fraudulent or impersonated companies to acquire valid certificates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.