TRUSTTRAP is a credential-harvesting malware used by the Iran-linked threat cluster UNC1549, also known as Nimbus Manticore and Subtle Snail. Mandiant reporting describes it as malware that presents Windows pop-up prompts to trick users into entering their Microsoft account credentials. It has been used in UNC1549 intrusions targeting aerospace, aviation, and defense organizations in the Middle East, and is part of a broader post-compromise toolset that supports reconnaissance, persistence, tunneling, credential theft, and long-term access. High-confidence behavior directly described in the source is limited to displaying fake Windows prompts for Microsoft credential capture. The associated campaign gained initial access through spear-phishing, abuse of third-party relationships, and use of stolen credentials for platforms such as Azure Virtual Desktop, Citrix, and VMware. No specific IOCs for TRUSTTRAP are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"TRUSTTRAP, a malware that serves a Windows prompt to trick the user into entering their Microsoft account credentials"
"TRUSTTRAP, a malware that serves a Windows prompt to trick the user into entering their Microsoft account credentials"
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to lure/collect Microsoft account credential inputs (credential harvesting).
Credential phishing/stealing malware that presents a Windows prompt to capture Microsoft account credentials from the user.
Social-engineering utility that displays Windows pop-up prompts to trick users into entering credentials.
Social-engineering utility that displays Windows pop-up prompts to trick users into entering credentials.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.