logo

UNC1549__2024__When_Cats_Fly_Suspected_Iranian_Threat_Actor_UNC1549_Targets_Israeli_and_Middle_East_Aerospace_and_Defense_Sectors_Mandiant.pdf

ID: 59aed1d6-e751-4df5-b267-7732c455bd6c

STIX ID: report--59aed1d6-e751-4df5-b267-7732c455bd6c

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2024-03-13

Last Modified Date: 2024-03-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant reports a suspected Iran-nexus espionage campaign attributed to UNC1549, focusing on Middle East aerospace, aviation, and defense entities (notably Israel and the UAE) with potential reach to Turkey, India, and Albania. The operation relies on social-engineering lures and fake job offers to deliver backdoors MINIBIKE and MINIBUS via Azure-based C2 and a tunneler named LIGHTRAIL, and has been active since 2022 with ongoing activity into 2024, indicating a sophisticated, geographically targeted malware campaign.