Screening Serpens is an Iran-nexus cyberespionage group active since at least 2022. It is tracked as UNC1549 by Mandiant, Smoke Sandstorm by Microsoft, and is commonly associated with Iranian Dream Job activity. The group is aligned with Iranian intelligence objectives and conducts tailored recruitment-themed social-engineering campaigns to obtain covert, long-term access to targeted organizations. Screening Serpens has targeted technology, aerospace, defense, satellite communications, telecommunications, research and development, and defense-logistics organizations. Confirmed targeting includes organizations in the United States, Israel, the United Arab Emirates, the United Kingdom, France, Germany, and other Middle Eastern countries. The group uses spear-phishing lures impersonating recruitment portals, job opportunities, and videoconferencing services. Its intrusion chains have used user-executed malicious archives, DLL sideloading through legitimate signed executables, and AppDomainManager hijacking in .NET Framework applications. The latter technique causes malicious code to load early in application initialization and has been used to impair telemetry and bypass strong-name validation. Screening Serpens has also established persistence through scheduled tasks and Registry Run Keys. Recent activity deployed MiniUpdate and MiniJunk V2 remote-access trojans. These implants support command execution, process and file operations, payload loading, and data collection and exfiltration, including chunked file uploads in newer variants. The group rotates command-and-control infrastructure by target and malware variant, primarily using Azure-hosted web services and HTTPS, while varying command mappings and applying obfuscation to hinder signature-based detection. Behavioral detection of suspicious .NET configuration changes, sideloaded unsigned modules, abnormal scheduled-task or Run Key creation, and recurring HTTPS beaconing is more resilient than static-indicator detection for this activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian intelligence-linked cyber-espionage cluster conducting coordinated campaigns using MiniUpdate and MiniJunk V2 RATs for persistent access and confidential-data collection. It uses recruitment-themed spear-phishing, DLL sideloading, AppDomainManager hijacking, Azure-hosted and per-campaign segmented C2 infrastructure, and web-based exfiltration.
Using tailored recruitment-themed phishing lures to deploy remote-access tools against targets in the United States, Israel, the UAE, and other Middle East countries.
Iran-linked cyber-espionage group active since at least 2022, targeting aerospace, defense, technology, R&D, satellite communications, and defense logistics organizations via Dream Job-style spear-phishing to gain long-term covert access for intelligence collection.
Espionage campaigns using recruitment-themed social engineering, including tailored lures and new RAT variants, aligned with IRGC strategic priorities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.