GhostLine is a custom Golang-based Windows tunneler used by the Iran-linked espionage cluster UNC1549, also referred to as Nimbus Manticore and Subtle Snail, and associated in broader reporting with Tortoiseshell activity. It is used for covert communications and command-and-control, including stealthy tunneling and data exfiltration. Reporting describes GhostLine as using a hard-coded domain for communication, and as part of a broader post-exploitation toolkit that also includes LIGHTRAIL and POLLBLEND tunnelers, along with backdoors and credential theft utilities such as MINIBIKE, TWOSTROKE, DEEPROOT, CRASHPAD, DCSYNCER.SLICK, SIGHTGRAB, and TRUSTTRAP. GhostLine has been observed in intrusions targeting aerospace, aviation, defense, telecommunications, and related high-value organizations in the Middle East and Europe. UNC1549 commonly gained access through spear-phishing, stolen credentials, abuse of third-party relationships, and access to remote platforms such as Citrix, VMware, and Azure Virtual Desktop, then used DLL search order hijacking to execute payloads including GhostLine. The campaign emphasized long-term persistence, stealth, and resilient re-entry, with malicious binaries often masquerading as legitimate software from vendors such as FortiGate, Microsoft, NVIDIA, Citrix, and VMware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Over subsequent years, the group layered in additional tooling — MiniJunk, MiniBrowse, DCSyncer.Slick, DeepRoot, GhostLine, LightRail, and others...
"GHOSTLINE, a Golang-based Windows tunneler that uses a hard-coded domain for its communication"
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
"UNC1549 abused DLL search order hijacking to execute CRASHPAD, DCSYNCER.SLICK, GHOSTLINE, LIGHTRAIL, MINIBIKE, POLLBLEND, SIGHTGRAB, and TWOSTROKE payloads... installed the legitimate software after initial access in order to abuse SOH... replaced or added the malicious DLLs within the legitimate installation directory, typically with SYSTEM privileges."
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of Tortoiseshell’s modular toolkit used for tunneling or persistent access within victim networks.
Tunneling tool used for covert command-and-control and data exfiltration by disguising malicious traffic within legitimate cloud communications.
Tunneling tool used during intrusions (likely for covert C2/traffic forwarding).
Golang Windows tunneler that communicates via a hard-coded domain to support stealthy C2/traffic forwarding.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.