UNC1549 (Proofpoint's TA455) is a suspected Iranian IRGC-nexus espionage actor active since mid-2022 that uses recruitment- and hostage-themed 'dream job' lures and Azure-hosted infrastructure to deploy the MINIBIKE and MINIBUS backdoors against aerospace, aviation, defense, and telecom targets in Israel, the UAE, Turkey, and Europe.
External aliases
via 1 crosswalk source
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
UNC1549 was detailed by Google/Mandiant in February 2024 ('When Cats Fly') as a suspected Iranian threat actor targeting Israeli and Middle Eastern aerospace, aviation, and defense organizations. Mandiant assesses an Iran-nexus with moderate confidence and notes overlaps with the Smoke Sandstorm and Crimson Sandstorm clusters; Proofpoint tracks closely related activity as TA455 and observes a disputed overlap with Tortoiseshell/Imperial Kitten that vendors do not fully reconcile — an attribution ambiguity preserved here rather than resolved.
The group's hallmark is elaborate, sustained social engineering: fabricated recruiting personas and fake job portals (including 'Bring Them Home Now' hostage-themed lures tied to the Gaza conflict) delivered via LinkedIn and spoofed HR sites. Payloads are the C++ MINIBIKE backdoor (file exfiltration, upload, and command execution) and its more capable successor MINIBUS, with the LIGHTRAIL tunneler for C2. A defining tradecraft trait is heavy abuse of Microsoft Azure cloud infrastructure for C2 and staging, letting malicious traffic blend into trusted cloud services and complicating network detection.
→Phishing: Spearphishing via ServicetechniqueATT&CK mapping
→Establish Accounts: Social Media AccountstechniqueATT&CK mapping
MENA targeting concentrates on Israel and the UAE, with secondary victims in Turkey and India, focused on aerospace, aviation, defense manufacturing, and thermal-imaging firms — verticals aligned to Iranian military-intelligence collection. In late 2024 ClearSky and others documented related aviation-sector 'dream job' operations delivering the SnailResin and SlugResin malware families.
Activity continued into 2025: Check Point reported in September 2025 that UNC1549 had compromised 34 devices across 11 telecommunications organizations, expanding its recruitment-lure operations to European targets with heightened focus on Denmark, Sweden, and Portugal — evidence of a persistent, geographically broadening campaign.
Notable campaigns
2024
When Cats Fly / MINIBIKE-MINIBUS
Mandiant-documented espionage against Israeli, UAE, and Turkish aerospace and defense firms using job/hostage-themed lures, MINIBIKE/MINIBUS backdoors, and Azure C2.
2024
Dream Job / SnailResin
Aviation-sector 'dream job' recruitment lures delivering the SnailResin and SlugResin malware families via LinkedIn personas.
2025
European telecom intrusion set
Check Point-reported compromise of 34 devices across 11 telecom firms, expanding recruitment-lure espionage to Denmark, Sweden, and Portugal.
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.