Skip to main content
Mallory
MalwareUsed by 3 actors

DeepRoot

DEEPROOT is a custom backdoor used by the Iran-linked threat cluster UNC1549, also tracked as Nimbus Manticore and associated in reporting with Tortoiseshell. It has been used in espionage campaigns targeting aerospace, aviation, defense, and in some reporting telecommunications organizations across the Middle East, Europe, the U.S., and other regions from at least late 2023 through 2025. Multiple sources in the provided content describe DEEPROOT as a Golang-based Linux backdoor and as the Linux counterpart to TWOSTROKE. Its documented capabilities include shell command execution, system information enumeration, and file operations including deletion, upload, and download. Reporting also places DEEPROOT in Dream Job-style and recruitment-themed social-engineering campaigns, including resume and personality-test style delivery chains, alongside other UNC1549 malware such as MINIBIKE, TWOSTROKE, CRASHPAD, LIGHTRAIL, GHOSTLINE, POLLBLEND, DCSYNCER.SLICK, SIGHTGRAB, and TRUSTTRAP. The broader intrusion set used spear-phishing, stolen credentials, abuse of third-party relationships, and access to remote platforms such as Azure Virtual Desktop, Citrix, and VMware; however, the content specifically attributes DEEPROOT itself to post-compromise backdoor functionality rather than initial access. High-confidence behavior directly attributed to DEEPROOT is limited to shell execution, host/system enumeration, and file management on Linux systems.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Magic Hound

The group is also linked to attacks on aviation and defense organizations across the Middle East between 2023 and 2025, deploying backdoors such as MINIBIKE, TWOSTROKE and DEEPROOT.

via scworldscworld.com
Subtle Snail

"DEEPROOT, a Golang-based Linux backdoor that supports shell command execution, system information enumeration, and file operations"

via the hacker newsthehackernews.com
UNC6446

Iranian groups deploy MINIBIKE, TWOSTROKE, DEEPROOT, and CRASHPAD in Dream Job-style campaigns...

via rescana blogrescana.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

Common TTPs across these campaigns include spearphishing, supply chain compromise, drive-by downloads, malicious RDP and LNK files, credential dumping, obfuscated payloads, and encrypted command and control (C2) channels.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.