FlagThis
← Threat Actors
/
Iran
/
UNC1549
DOSSIER // UNC1549
UNC1549
ACTIVE CAMPAIGN TRACKED
▲ High Threat
Iran
Primary Aliases:
Nimbus Manticore
🔍 Adversary Rosetta Stone (1) ▾
📋 Copy All
Sponsor / State Affiliation
Iran (State-sponsored)
Primary Motivation
Cyber Espionage and Intelligence Gathering
Active Timeline
Unknown – Present
Confidence Rating
85% (Grounded)
Middle East Infrastructure Infiltration, Edge Device Vulnerability Exploitation Campaign
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Government Agencies
Critical Infrastructure
Telecommunications
Energy Sector
Defense Contractors
🛡️ MITRE ATT&CK® Attack Lifecycle
(6 TTPs)
📥 Download Navigator JSON
All Stages
6
Initial Access
2
Execution
2
Credential Access & Discovery
1
Command & Control
1
Initial Access
2
T1566
Exploitation of Edge Network Devices (VPNs, Firewalls)
↗
T1566
Spearphishing via Social Engineering
↗
Execution
2
T1059
Living-off-the-Land (LotL) techniques
↗
T1059
Lateral Movement via PowerShell and WMI
↗
Credential Access & Discovery
1
T1003
Credential Harvesting
↗
Command & Control
1
T1071
Custom Malware Deployment (Backdoors)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
Nimbus Manticore Espionage Toolset Expansion: TWOSTROKE-Variant and Reverse SSH Tunneling
Strategies and Tactics
2026-08-28
Adversary Rosetta Stone // UNC1549
×
🛡️ Other Industry Tracking Codes
Nimbus Manticore
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD