Mandiant reported that UNC1549 targeted aerospace and defense organizations with post-compromise spear-phishing aimed at IT staff and administrators, using reconnaissance from breached inboxes and internal password-reset workflows to steal higher-privilege credentials. The group deployed several custom tools and backdoors, including MINIBIKE, TWOSTROKE, DEEPROOT, and the LIGHTRAIL tunneler, while heavily abusing DLL search-order hijacking against legitimate software from vendors such as Fortinet, VMware, Citrix, Microsoft, and NVIDIA. TWOSTROKE communicated over SSL on TCP/443 and supported file transfer, execution, in-memory DLL loading, and host discovery, while LIGHTRAIL used Azure-backed WebSocket infrastructure to tunnel traffic and evade detection.
The activity aligns closely with earlier reporting on the Iranian-aligned Mirage Kitten espionage group, whose malware set included the NightLedger backdoor and the ArcBridge and BridgeHead tunnelers used against aerospace, aviation, defense, telecommunications, government, and financial targets across the Middle East and Africa. Securelist said NightLedger also relied on DLL hijacking by masquerading as SspiCli.dll, and its tunnelers provided covert WebSocket-based relay capability with enterprise proxy-aware authentication. The overlap in victimology, tradecraft, and tunneling design suggests UNC1549 is operating with a malware ecosystem strongly connected to Mirage Kitten’s previously documented toolset.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Mandiant reported that UNC1549 targeted the aerospace and defense ecosystem using spear-phishing against IT staff and administrators after initial breaches to obtain higher-privilege credentials. The report detailed custom tools and malware including MINIBIKE, TWOSTROKE, DEEPROOT, and the LIGHTRAIL tunneler, as well as extensive DLL search order hijacking and uniquely hashed payloads to hinder detection and forensics.
Securelist reported a Mirage Kitten cyber-espionage campaign and attributed a previously undocumented malware set to the Iranian-aligned group, including the NightLedger backdoor and the ArcBridge and BridgeHead tunnelers. The activity targeted organizations in sectors including aerospace, aviation, defense, telecommunications, government, SMB, and finance across the Middle East and Africa.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecloud.google.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.