Nimbus Manticore is an Iranian state-sponsored cyber-espionage actor assessed to be affiliated with the Islamic Revolutionary Guard Corps. It is widely tracked as UNC1549 and Smoke Sandstorm, and has also been reported as GalaxyGato, Mirage Kitten, Subtle Snail, and Screening Serpens. The group has conducted sustained intelligence-collection operations against aerospace, aviation, defense, telecommunications, software, government, financial, and other strategically relevant organizations across the Middle East, Africa, South Asia, Europe, Australia, and the United States. Nimbus Manticore is particularly associated with recruitment-themed social engineering. Its operators impersonate recruiters, employers, and prominent aerospace or aviation brands through tailored spear-phishing, fake career portals, fraudulent videoconferencing invitations, and job-description lures. More recent activity also included search-engine optimization poisoning that impersonated legitimate software-download sites. These campaigns deliver multi-stage malware through trusted or signed software components, .NET AppDomainManager hijacking, DLL sideloading, and malicious configuration abuse. The actor has deployed multiple custom implants and supporting tools, including MiniJunk, MiniFast, MiniBrowse, NightLedger, TWOSTROKE, and DEEPROOT. Its backdoors provide host and network reconnaissance, process and directory enumeration, command execution, file and DLL operations, screenshot capture, data upload and download, remote tasking, and scheduled-task persistence. MiniBrowse has been used to collect browser-stored credentials. Nimbus Manticore also uses bespoke tunneling utilities, including WebSocket- and SOCKS-based proxies, to relay operator traffic through compromised systems and maintain covert access. Recent malware exhibits increased obfuscation, use of cloud-hosted command-and-control infrastructure, anti-analysis logic, and in some cases indicators of AI-assisted development.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a prior example of reverse SSH tunneling techniques; the content does not attribute the described Tortoiseshell activity to UNC1549.
Suspected Iran-linked threat actor conducting recruitment-themed intrusion activity and abusing compromised supplier/partner accounts to access aerospace and defense targets.
Referenced as likely using AI-assisted development to build a new backdoor, illustrating the article’s broader point about AI lowering barriers for offensive cyber capability.
Conducting state-backed intrusion campaigns across the Middle East, Africa, and South Asia using the NightLedger Windows backdoor and custom WebSocket tunnelers BridgeHead and ArcBridge to maintain covert access. The group is also described as using tailored job opportunity-themed phishing lures, lookalike videoconferencing pages, malicious archives on third-party file-sharing services, DLL side-loading, and bespoke tunneling utilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.