An Iranian state-sponsored threat group tracked as UNC1549, also known as Nimbus Manticore or Subtle Snail, has intensified its cyber-espionage operations against aerospace, aviation, and defense sectors across the Middle East, Israel, the US, and several European countries. The group, believed to have ties to the Iranian Revolutionary Guard Corps (IRGC), has leveraged sophisticated initial access techniques, including spear-phishing, abuse of third-party relationships, and exploitation of remote access software such as Citrix, VMWare, and Azure Virtual Desktop. UNC1549 has demonstrated a strategic focus on supply chain attacks, often infiltrating less-secure third-party partners to pivot into their primary targets, and has broadened its operational scope to include technology, hospitality, and transportation sectors as stepping stones to ultimate targets.
Recent investigations by Google-owned Mandiant and corroborated by multiple security sources have revealed that UNC1549 has developed and deployed a suite of custom malware backdoors, including TWOSTROKE, DEEPROOT, Crashpad, Dcsyncer.slick, Ghostline, Pollblend, and Sightgrab. These tools are used to establish persistent access and exfiltrate sensitive data, with each post-exploitation payload observed having a unique hash, indicating a high level of operational security. The group’s activities since mid-2024 reflect a significant leap in sophistication, with a marked increase in espionage aligned with Iranian state interests, particularly targeting Israel and expanding to other strategic regions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On November 18, 2025, Google-owned Mandiant publicly reported that UNC1549 had expanded and refined its operations against aerospace, aviation, and defense targets, often pivoting through third-party organizations in sectors such as technology, hospitality, and transportation. Mandiant detailed the actor's upgraded custom tooling, including DEEPROOT, TWOSTROKE, LIGHTRAIL, GHOSTLINE, POLLBLEND, CRASHPAD, DCSYNCER.SLICK, SIGHTGRAB, and TRUSTTRAP, and described stealth features such as reverse SSH tunnels, DLL hijacking, domain mimicry, and dormant backdoors.
PRODAFT previously connected the same threat actor to a recruitment-themed social engineering campaign on LinkedIn targeting European telecommunications firms. That activity reportedly led to breaches at 11 organizations, or nearly a dozen telecom firms.
Mandiant's reporting on UNC1549 was informed by incident response engagements beginning in mid-2024, during which the actor was seen using spear-phishing, stolen credentials, third-party access, and VDI or remote platform access to enter victim environments. The observed intrusions included post-exploitation actions such as reconnaissance, credential theft, lateral movement, and data theft.
Mandiant said the Iran-linked espionage cluster UNC1549, also known as Nimbus Manticore or Subtle Snail, has conducted compromises against aerospace, aviation, and defense organizations in the Middle East since late 2023. The campaign focused on espionage and long-term access, with Israel described as a central target.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.