SIGHTGRAB is a Windows utility used by the Iran-linked threat cluster UNC1549, also known as Nimbus Manticore and Subtle Snail, in espionage intrusions targeting aerospace, aviation, and defense organizations in the Middle East since late 2023. Mandiant described it as a C Windows utility selectively deployed to capture screenshots at regular intervals and save them to disk. Reporting also states that SIGHTGRAB was used for taking screenshots during post-compromise operations. UNC1549 commonly gained initial access through spear-phishing, exploitation of third-party relationships, and use of stolen credentials for platforms such as Azure Virtual Desktop, Citrix, and VMware, then used custom malware and utilities for reconnaissance, credential theft, privilege escalation, tunneling, persistence, and information theft. SIGHTGRAB was one of several Windows utilities and payloads deployed alongside tools such as CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, and TWOSTROKE. Mandiant reported that UNC1549 abused DLL search order hijacking to execute SIGHTGRAB and other payloads, often masquerading malicious components as legitimate software from vendors including FortiGate, Microsoft, NVIDIA, Citrix, and VMware, and in some cases installing legitimate software to facilitate the hijack. No specific indicators of compromise for SIGHTGRAB were provided in the content beyond its name, role, and execution via DLL search order hijacking.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"SIGHTGRAB, a C Windows utility, selectively deployed to capture screenshots at regular intervals and save them to disk"
"SIGHTGRAB, a C Windows utility, selectively deployed to capture screenshots at regular intervals and save them to disk"
1 distinct technique documented for this family, organized by ATT&CK tactic.
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows utility used during intrusions (specific function not described in the provided content).
Windows screenshot capture utility used for periodic screen collection and local storage.
Screenshot capture utility used for on-host surveillance and collection.
Screenshot capture utility used for on-host surveillance and collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.