POLLBLEND is a custom Windows tunneling utility associated with the Iranian state-aligned espionage group tracked as UNC1549, Nimbus Manticore, Mirage Kitten, Smoke Sandstorm, and Subtle Snail. It has been used in post-compromise operations alongside other bespoke implants and tunnelers such as LIGHTRAIL and GHOSTLINE as part of long-term covert access and operator communications within victim environments.
POLLBLEND is characterized as a C++ Windows tunneler that uses hard-coded command-and-control infrastructure to register itself and retrieve tunneling configuration. Its role is to relay communications for the operator after initial access, supporting stealthy post-exploitation activity rather than serving as the primary intrusion vector. Reporting also indicates the group has executed POLLBLEND through DLL search-order hijacking, consistent with its broader tradecraft of abusing legitimate software and side-loading malicious components to evade detection and blend into enterprise environments.
The malware has been observed in campaigns targeting aerospace, aviation, defense, telecommunications, government, and related sectors, particularly across the Middle East, with broader activity also affecting Africa and Europe through the same threat actor’s operations. POLLBLEND forms part of a wider intrusion ecosystem focused on persistence, covert access, and resilient command-and-control in support of cyber-espionage objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The use of BridgeHead and ArcBridge indicates the threat actor's continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND.
This aligns with previous public reporting, which documented the group’s use of the LIGHTRAIL and POLLBLEND tunnelers.
"POLLBLEND, a C++ Windows tunneler that uses hard-coded command-and-control (C2) servers to register itself and download tunneler configuration"
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A bespoke tunneling utility previously used by the threat actor, mentioned as historical background.
A previously reported tunneling utility used by Mirage Kitten, mentioned as part of the group’s historical tunneling tradecraft.
Tunneling tool used during intrusions (likely for covert C2/traffic forwarding).
C++ Windows tunneler that registers to hard-coded C2 and retrieves tunneling configuration for covert connectivity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.