#unc1549 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #unc1549, aggregated by home.social.
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
Mirage Kitten targets Middle East and Africa region with new malware
Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.
Pulse ID: 6a689c34d4df4bb1475d80c7
Pulse Link: https://otx.alienvault.com/pulse/6a689c34d4df4bb1475d80c7
Pulse Author: AlienVault
Created: 2026-07-28 12:10:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Africa #BackDoor #CyberSecurity #Edge #InfoSec #Malware #MiddleEast #Nim #OTX #OpenThreatExchange #Pakistan #Phishing #Proxy #RAT #SpearPhishing #Telecom #Telecommunication #Troll #UNC1549 #Windows #bot #AlienVault
-
Beyond the Battlefield: Threats to the Defense Industrial Base
#UNC3886 #UNC5221 #APT44 #TEMP.Vermin #UNC5125 #UNC5792 #UNC4221 #UNC5976 #UNC5114 #APT45 #APT43 #UNC2970 #UNC1549 #UNC6446 #APT5 #HeavenOfTheSlavs #APT1 #APT40 #VoltTyphoon #UNC6508 #UNC5203 #UNC5318
https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-base -
Beyond the Battlefield: Threats to the Defense Industrial Base
#UNC3886 #UNC5221 #APT44 #TEMP.Vermin #UNC5125 #UNC5792 #UNC4221 #UNC5976 #UNC5114 #APT45 #APT43 #UNC2970 #UNC1549 #UNC6446 #APT5 #HeavenOfTheSlavs #APT1 #APT40 #VoltTyphoon #UNC6508 #UNC5203 #UNC5318
https://cloud.google.com/blog/topics/threat-intelligence/threats-to-defense-industrial-base -
Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem
#UNC1549 #TWOSTROKE #LIGHTRAIL #DEEPROOT #GHOSTLINE #POLLBLEND
https://cloud.google.com/blog/topics/threat-intelligence/analysis-of-unc1549-ttps-targeting-aerospace-defense -
Frontline Intelligence: Analysis of UNC1549 TTPs, Custom Tools, and Malware Targeting the Aerospace and Defense Ecosystem
#UNC1549 #TWOSTROKE #LIGHTRAIL #DEEPROOT #GHOSTLINE #POLLBLEND
https://cloud.google.com/blog/topics/threat-intelligence/analysis-of-unc1549-ttps-targeting-aerospace-defense -
Iranian Hackers Use Fake Job Lures to Breach Europe’s Critical Industries https://hackread.com/iranian-hackers-fake-job-breach-europe-industries/ #NimbusManticore #SmokeSandstorm #Cybersecurity #CyberAttacks #CyberAttack #MiniBrowser #SlugResin #Security #Minibike #MiniJunk #Phishing #Malware #UNC1549 #europe #Iran #IRGC
-
Iranian Hackers Use Fake Job Lures to Breach Europe’s Critical Industries https://hackread.com/iranian-hackers-fake-job-breach-europe-industries/ #NimbusManticore #SmokeSandstorm #Cybersecurity #CyberAttacks #CyberAttack #MiniBrowser #SlugResin #Security #Minibike #MiniJunk #Phishing #Malware #UNC1549 #europe #Iran #IRGC