UNC1549__2024__When_Cats_Fly_Suspected_Iranian_Threat_Actor_UNC1549_Targets_Israeli_and_Middle_East_Aerospace_and_Defense_Sectors_Mandiant.pdf
ID: 59aed1d6-e751-4df5-b267-7732c455bd6c
STIX ID: report--59aed1d6-e751-4df5-b267-7732c455bd6c
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2024-03-13
Last Modified Date: 2024-03-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mandiant reports a suspected Iran-nexus espionage campaign attributed to UNC1549, focusing on Middle East aerospace, aviation, and defense entities (notably Israel and the UAE) with potential reach to Turkey, India, and Albania. The operation relies on social-engineering lures and fake job offers to deliver backdoors MINIBIKE and MINIBUS via Azure-based C2 and a tunneler named LIGHTRAIL, and has been active since 2022 with ongoing activity into 2024, indicating a sophisticated, geographically targeted malware campaign.
