UNK_SmudgedSerpent
UNK_SmudgedSerpent is a previously unidentified, Iran-linked threat activity cluster tracked by Proofpoint between June and August 2025. Proofpoint described it as a new Iranian APT/threat cluster but did not make a high-confidence attribution to a specific known group, instead noting overlapping tactics, techniques, procedures, and infrastructure with multiple Iranian state-aligned actors. Reported overlaps include TA453 (Charming Kitten, Mint Sandstorm), TA455 (Smoke Sandstorm, UNC1549, C5 Agent), and TA450 (MuddyWater, Mango Sandstorm). Proofpoint proposed possible explanations for the mixed signals including shared procurement or infrastructure, contractor or personnel overlap, training commonalities, reorganization, or collaboration between Iranian entities including the IRGC and MOIS. The cluster targeted U.S.-based academics, think-tank personnel, and foreign policy experts, especially individuals focused on Iran, the Middle East, the IRGC, and related policy issues. Campaigns used patient, human-centered social engineering, often beginning with benign email exchanges before progressing to phishing. The actor impersonated prominent U.S. foreign policy figures and institutions, including personas associated with the Brookings Institution and the Washington Institute, and in one campaign contacted more than 20 members of a U.S.-based think tank. Observed lures referenced domestic political unrest and societal reform in Iran, investigations into IRGC militarization, and Iran’s role in Latin America. The actor used collaboration-themed pretexts, spoofed OnlyOffice and Microsoft Teams or Microsoft 365 login experiences, and attacker-controlled health-themed domains such as thebesthomehealth[.]com and mosaichealthsolutions[.]com. Credential-harvesting pages were customized with victim information and, in some cases, employer branding. When credential theft appeared to fail or targets became suspicious, the actor continued engagement in the same thread and pivoted to malware delivery. In the malware-delivery phase, victims were directed to archives or MSI installers disguised as meeting or collaboration materials, including fake Microsoft Teams content. These installers deployed legitimate remote monitoring and management tools, notably PDQ Connect, and Proofpoint observed suspected hands-on-keyboard activity in which PDQ Connect was used to install a second RMM tool, ISL Online. Proofpoint noted that abuse of RMM tooling is generic but relatively uncommon among state-sponsored actors, while also documenting overlap with TA450 tradecraft. Related infrastructure analysis also identified OnlyOffice-hosted content and a TA455 custom backdoor lineage, including MiniJunk and MiniBike, on associated infrastructure, further complicating attribution. Proofpoint reported the activity as topical and sporadic, shifting from a broader initial target set to more isolated later targeting, and observed no further email campaign activity after early August 2025.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Commercial & Professional Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Where they're from
Attributed origin per open-source reporting.
- IR
Tradecraft
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Observables
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Human-centric espionage targeting US academics and policy experts through impersonation, credential harvesting, and follow-on persistent access using commercial remote management tools.
Conducting phishing and supply chain attacks targeting high-value individuals and enterprise networks, leveraging fake platforms and developer tools.
Suspected Iran-nexus espionage cluster targeting academics/foreign policy experts using social engineering rapport-building, benign conversation starters, themed infrastructure, file-hosting spoofs, and RMM tooling; attribution overlaps with multiple known Iranian groups.
Targeted Iranian-aligned espionage activity against U.S. policy experts using social engineering, credential phishing, and follow-on tooling (MSI delivery leading to RMM) consistent with hands-on-keyboard intrusion.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.