Skip to main content
Mallory
🇮🇷 IR3 malware families

UNK_SmudgedSerpent

Also known asunk_smudgedserpent

UNK_SmudgedSerpent is a previously unidentified, Iran-linked threat activity cluster tracked by Proofpoint between June and August 2025. Proofpoint described it as a new Iranian APT/threat cluster but did not make a high-confidence attribution to a specific known group, instead noting overlapping tactics, techniques, procedures, and infrastructure with multiple Iranian state-aligned actors. Reported overlaps include TA453 (Charming Kitten, Mint Sandstorm), TA455 (Smoke Sandstorm, UNC1549, C5 Agent), and TA450 (MuddyWater, Mango Sandstorm). Proofpoint proposed possible explanations for the mixed signals including shared procurement or infrastructure, contractor or personnel overlap, training commonalities, reorganization, or collaboration between Iranian entities including the IRGC and MOIS. The cluster targeted U.S.-based academics, think-tank personnel, and foreign policy experts, especially individuals focused on Iran, the Middle East, the IRGC, and related policy issues. Campaigns used patient, human-centered social engineering, often beginning with benign email exchanges before progressing to phishing. The actor impersonated prominent U.S. foreign policy figures and institutions, including personas associated with the Brookings Institution and the Washington Institute, and in one campaign contacted more than 20 members of a U.S.-based think tank. Observed lures referenced domestic political unrest and societal reform in Iran, investigations into IRGC militarization, and Iran’s role in Latin America. The actor used collaboration-themed pretexts, spoofed OnlyOffice and Microsoft Teams or Microsoft 365 login experiences, and attacker-controlled health-themed domains such as thebesthomehealth[.]com and mosaichealthsolutions[.]com. Credential-harvesting pages were customized with victim information and, in some cases, employer branding. When credential theft appeared to fail or targets became suspicious, the actor continued engagement in the same thread and pivoted to malware delivery. In the malware-delivery phase, victims were directed to archives or MSI installers disguised as meeting or collaboration materials, including fake Microsoft Teams content. These installers deployed legitimate remote monitoring and management tools, notably PDQ Connect, and Proofpoint observed suspected hands-on-keyboard activity in which PDQ Connect was used to install a second RMM tool, ISL Online. Proofpoint noted that abuse of RMM tooling is generic but relatively uncommon among state-sponsored actors, while also documenting overlap with TA450 tradecraft. Related infrastructure analysis also identified OnlyOffice-hosted content and a TA455 custom backdoor lineage, including MiniJunk and MiniBike, on associated infrastructure, further complicating attribution. Proofpoint reported the activity as topical and sporadic, shifting from a broader initial target set to more isolated later targeting, and observed no further email campaign activity after early August 2025.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Commercial & Professional Services

Where they target

Geographies tied to known operations.

  • 🇺🇸 United States

Where they're from

Attributed origin per open-source reporting.

  • IR
MITRE ATT&CK

Tradecraft

9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

8 of 15 tactics13 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002×2
Spearphishing Link
TA0002
Execution
1 technique
T1204
User Execution
T1204.001
Malicious Link
TA0003
Persistence
1 technique
T1078
Valid Accounts
TA0004
Privilege Escalation
1 technique
T1078
Valid Accounts
TA0005
Stealth
2 techniques
T1078
Valid Accounts
T1218
System Binary Proxy Execution
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0011
Command and Control
1 technique
T1105
Ingress Tool Transfer
IOCS

Observables

7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping9

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables7

Domains, IPs, and hashes tied to this actor, refreshed continuously.