FlagThis
← Threat Actors
/
Iran
/
UNC1549
DOSSIER // UNC1549
UNC1549
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Iran
Primary Aliases:
Nimbus Manticore
📋 Copy All
Sponsor / State Affiliation
Iran (State-sponsored)
Primary Motivation
Cyber Espionage and Intelligence Gathering
Confidence Rating
85% (Grounded)
Regional Intelligence Gathering Operations
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
🎯 Target Sectors & Focus
Government
Defense
Critical Infrastructure
Telecommunications
Diplomatic Entities
Middle Eastern Regional Organizations
🛡️ MITRE ATT&CK® Attack Lifecycle
(6 TTPs)
📥 Download Navigator JSON
All Stages
6
Initial Access
2
Execution
1
Credential Access & Discovery
1
Command & Control
2
Initial Access
2
T1566
Spear-phishing with malicious attachments
↗
T1566
Exploitation of public-facing edge devices (VPNs/Firewalls)
↗
Execution
1
T1059
Living-off-the-land (LotL) techniques
↗
Credential Access & Discovery
1
T1003
Credential harvesting
↗
Command & Control
2
T1071
Custom malware/backdoor deployment
↗
T1071
Command and Control (C2) via legitimate cloud services
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Nimbus Manticore Espionage Toolset Expansion: TWOSTROKE-Variant and Reverse SSH Tunneling
Strategies and Tactics
2026-08-28
Adversary Rosetta Stone // UNC1549
×
🛡️ Other Industry Tracking Codes
Nimbus Manticore
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD