Threat Actor ๐Ÿ‡ฎ๐Ÿ‡ท Iran

UNC1549

Also known as: Nimbus Manticore

UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.

Indicators of Compromise 46

Domain aecert[.]org Domain buisness-centeral-transportation[.]com Domain business-deegital[.]azurewebsites[.]net Domain business-deegital[.]com Domain business-startup[.]azurewebsites[.]net Domain businessdeegital[.]azurewebsites[.]net Domain businessmixture[.]com Domain businessstartup[.]azurewebsites[.]net Domain global-reds[.]com Domain healthcarezoom-centeral[.]azurewebsites[.]net Domain healthcarezoomcenteral[.]azurewebsites[.]net Domain healthcarezoomcenteral[.]org Domain maadinglobal[.]com Domain neexportfolio[.]azurewebsites[.]net Domain neexportfolio[.]com Domain plugplay[.]azurewebsites[.]net Domain realhealthshop[.]com Domain rgbteller[.]azurewebsites[.]net Domain smartconnect[.]azurewebsites[.]net Domain thehealth-life[.]com Domain tjconsultingservices[.]com Domain toadreport[.]azurewebsites[.]net Domain wslwebui[.]azurewebsites[.]net Filename Front-Technical-Challenge.zip Filename GitHub Copilot Helper Filename IPHLPAPI.dll Filename RankChallenge-react-6uJSX3-main.zip Filename ctf-server Filename libwinpthread-1.dll Filename node_modules/.cache/.320697f1/index.js Filename server.js Filename sspicli.dll Filename unbcl.dll MD5 42f847597109da2a220391bb09d00676 MD5 5fa15ef96808ea82f0a6176f0bb4b386 MD5 6038d42af0affd1fb263f470c0956f6b MD5 a239e655709a2518dd0b7bdbed163679 MD5 ae628efa305387b633dce82f9364875b MD5 afb1c1583606599c7272cfb33cc6f498 MD5 c832ecd135781b11f59e3fffb3d2b6ac MD5 c90f0efadbf322e5eb1c4103a38c30e6 MD5 d09b14a2fe01c7363ecc56f5d046162c MD5 f7d36cc5904a53252d2bb3d21615134f IP 172[.]86[.]98[.]113 Package colorized_terminal@2.1.0 Package pretty-log@2.1.0

MITRE ATT&CK TTPs 27

Source Articles

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian threat actor Nimbus Manticore, also known as Iranian Dream Job, is using fake job recruitment lures on platforms like LinkedIn to deliver two newly identified cross-platform remote access trojans (RATs): NodeRabbit and PollCat. These malware families are distributed via trojanized coding challenge archives that contain malicious npm packages or JavaScript code, targeting developers on Windows, Linux, and macOS. The attacks enable command execution, file manipulation, persistence, and reconnaissance, with C2 infrastructure hosted on Azure and communication through specific API endpoints. The group's shift to Node.js-based cross-platform tools expands its reach while maintaining its historical social engineering tactics for cyber espionage in the Middle East and Africa.
hacker-news ยท1d ago
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an APT group also known as UNC1549, is conducting cyber-espionage operations targeting aerospace, defense, telecommunications, and government sectors in the Middle East and Africa. The group uses spear-phishing and fake recruitment portals to deploy new malware tools, including NightLedger, a Windows backdoor that performs reconnaissance, command execution, and data exfiltration, and two WebSocket-based tunneling tools, BridgeHead and ArcBridge, which enable covert C2 communications and SOCKS5 tunneling through compromised hosts. The infrastructure includes domains hosted on Azure and Cloudflare, with targeting logic based on username checks to avoid execution in unintended environments.
securelist ยท1mo ago
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Iranian state-backed threat actor Nimbus Manticore is conducting cyber espionage operations across the Middle East, Africa, and South Asia using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge. The group leverages phishing lures and fake videoconferencing pages to deliver payloads, which are executed via DLL side-loading. NightLedger enables reconnaissance, command execution, file operations, and screenshot capture, while BridgeHead and ArcBridge establish covert relay tunnels through victim systems for operator-controlled traffic.
hacker-news ยท1mo ago