POLLBLEND is a custom Windows tunneling utility associated with the Iran-aligned espionage group UNC1549, also tracked as Mirage Kitten, Smoke Sandstorm, Nimbus Manticore, and Subtle Snail. It has been used in post-compromise operations against organizations in sectors including aerospace, aviation, defense, telecommunications, government, and finance, primarily across the Middle East and Africa. The malware is part of a broader UNC1549 toolkit that emphasizes covert access, long-term persistence, and resilient operator communications inside victim environments.
POLLBLEND is described as a C++ Windows tunneler that uses hard-coded command-and-control infrastructure to register itself and retrieve tunneling configuration. Its role is to provide covert communications and network access for operators after initial intrusion, aligning it with other UNC1549 tunneling tools such as LIGHTRAIL and GHOSTLINE. Reported intrusions indicate the group commonly deploys such tunnelers after gaining access through spearphishing, stolen credentials, or abuse of trusted remote access and collaboration platforms.
UNC1549 has repeatedly used DLL search-order hijacking to execute POLLBLEND and other payloads, often by pairing malicious components with legitimate software from enterprise vendors or by installing legitimate software specifically to facilitate hijack-based execution. This tradecraft supports defense evasion and persistence while blending malicious activity into normal application behavior. POLLBLEND therefore fits into a mature post-exploitation workflow focused on stealthy communications, victim-specific operational security, and sustained espionage access rather than disruptive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This aligns with previous public reporting, which documented the group’s use of the LIGHTRAIL and POLLBLEND tunnelers.
"POLLBLEND, a C++ Windows tunneler that uses hard-coded command-and-control (C2) servers to register itself and download tunneler configuration"
"POLLBLEND, a C++ Windows tunneler that uses hard-coded command-and-control (C2) servers to register itself and download tunneler configuration"
1 distinct technique documented for this family, organized by ATT&CK tactic.
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously reported tunneling utility used by Mirage Kitten, mentioned as part of the group’s historical tunneling tradecraft.
Tunneling tool used during intrusions (likely for covert C2/traffic forwarding).
C++ Windows tunneler that registers to hard-coded C2 and retrieves tunneling configuration for covert connectivity.
Tunneling tool used to facilitate command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.