RaqibCTI Search the threat graph — actor, CVE, technique, victim…⌘K
UNC1549 / TA455 · APT / State-sponsored · RaqibCTI
Knowledge / Actors / UNC1549 / TA455 Corpus APT / State-sponsored
TA455 Smoke Sandstorm Yellow Dev 13 BOHRIUM
Attribution
Iran — suspected IRGC-nexus (moderate confidence per Mandiant)
Attribution confidence
medium
MENA targeting
Israel, UAE (primary); Turkey (secondary)
Sectors
Aerospace, aviation, defense, thermal-imaging manufacturing, telecom
Corpus activity · 6mo 2 mentions
Jul 2026: 1 Aug 2026: 1 A M J J A S
Why it matters State-sponsored / APT actor, medium confidence, documented targeting Israel, UAE (primary); Turkey (secondary) (Aerospace, aviation, defense sectors).
What's next No pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Coverage robustness · vs this actor How evasion-resistant our detection coverage is against UNC1549 / TA455's techniques — Summiting the Pyramid scores analytics (1 brittle – 5 robust); the actor inherits through its TTPs. This is a detection-engineering metric, not an attribution signal — see Attribution for confidence.
Techniques with a robust rule
0%
Techniques with any detection
4 / 7
Mean robustness (of covered)
2
actor
Technique overlap
← UNC1549 / TA455 · NightLedger campaign Correlated cluster 2026-08-12
← 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=en report ORKL 2026-03-25
← eset-apt-activity-report-q2-2025-q3-2025.pdf report ORKL 2025-10-30
← Mandiant M-Trends 2025 Report report ORKL 2025-04-24
← Investigating Iranian Intrusion into Strategic Middle East Critical Infrastructure report ORKL 2025-03-07
← Iranian "Dream Job" campaign report ORKL 2024-11-12
← When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors report ORKL 2024-03-13
← Staying ahead of threat actors in the age of AI report ORKL 2024-02-20
← Israel-Hamas War in Cyber February 2024 Tool of First Resort report ORKL 2024-02-08 Uses
→ Exfiltration Over C2 Channel technique ATT&CK mapping → Web Service technique ATT&CK mapping → Acquire Infrastructure: Domains technique ATT&CK mapping → User Execution: Malicious File technique ATT&CK mapping → Protocol Tunneling technique ATT&CK mapping → Phishing: Spearphishing via Service technique ATT&CK mapping → Establish Accounts: Social Media Accounts technique ATT&CK mapping
Suggested · co-occurring (unverified)
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.
Malware NightLedger co-mentioned in 2 items Malware ArcBridge co-mentioned in 2 items Malware BridgeHead co-mentioned in 2 items Sector Aerospace/Telecom (implied by Mirage Kitten targeting) co-mentioned in 1 item Technique T1195 co-mentioned in 1 item Country Russia co-mentioned in 1 item Malware Creduz co-mentioned in 1 item Technique T1476 co-mentioned in 1 item Sector Diplomatic organizations co-mentioned in 1 item Malware MobiDash co-mentioned in 1 item Sector Public sector co-mentioned in 1 item Malware Anatsa co-mentioned in 1 item Malware Trojan-Dropper.AndroidOS.Banker co-mentioned in 1 item Malware PowerCloud co-mentioned in 1 item Technique T1204.002 co-mentioned in 1 item Country Middle East (implied by Mirage Kitten's regional focus) co-mentioned in 1 item Malware HiddenAd co-mentioned in 1 item Malware Umbrij co-mentioned in 1 item Technique T1528 co-mentioned in 1 item Technique T1572 co-mentioned in 1 item Sector Corporate email/communications co-mentioned in 1 item Technique T1071 co-mentioned in 1 item Malware Mamont co-mentioned in 1 item Malware Cleanova loader co-mentioned in 1 item Sector Financial (banking users) co-mentioned in 1 item Country Belarus co-mentioned in 1 item Technique T1090.003 co-mentioned in 1 item Technique T1566 co-mentioned in 1 item Country Tanzania co-mentioned in 1 item Sector SMB co-mentioned in 1 item