RaqibCTI Search the threat graph — actor, CVE, technique, victim…⌘K
UNC1549 / TA455 · APT / State-sponsored · RaqibCTI
Knowledge / Actors / UNC1549 / TA455 Corpus APT / State-sponsored
TA455 Smoke Sandstorm Yellow Dev 13 BOHRIUM
Attribution
Iran — suspected IRGC-nexus (moderate confidence per Mandiant)
Attribution confidence
medium
MENA targeting
Israel, UAE (primary); Turkey (secondary)
Sectors
Aerospace, aviation, defense, thermal-imaging manufacturing, telecom
Corpus activity · 6mo 2 mentions
Jul 2026: 1 Aug 2026: 1 A M J J A S
Why it matters State-sponsored / APT actor, medium confidence, documented targeting Israel, UAE (primary); Turkey (secondary) (Aerospace, aviation, defense sectors).
What's next No pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.
Observed techniques 7 distinct Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Technique Name Tactic Observed use T1102 ↗ inferred Web Service Command and Control heavy abuse of Microsoft Azure cloud infrastructure for C2 and staging (Mandiant) T1572 ↗ inferred Protocol Tunneling Command and Control uses the LIGHTRAIL tunneler for C2 (Mandiant) T1204.002 ↗ inferred User Execution: Malicious File Execution targets open lure files delivering MINIBIKE/MINIBUS (Mandiant) T1041 ↗ inferred Exfiltration Over C2 Channel Exfiltration MINIBIKE performs file exfiltration and command execution (Mandiant) T1566.003 ↗ inferred Phishing: Spearphishing via Service Initial Access recruitment 'dream job' lures via LinkedIn personas (Mandiant/Proofpoint) T1583.001 ↗ inferred Acquire Infrastructure: Domains Resource Development spoofed HR sites and fake job portals (Mandiant/ClearSky)
actor
Technique overlap
← UNC1549 / TA455 · NightLedger campaign Correlated cluster 2026-08-12
← 2026_YIR_ExecutiveBriefing%20O_G.pdf?hsLang=en report ORKL 2026-03-25
← eset-apt-activity-report-q2-2025-q3-2025.pdf report ORKL 2025-10-30
← Mandiant M-Trends 2025 Report report ORKL 2025-04-24
← Investigating Iranian Intrusion into Strategic Middle East Critical Infrastructure report ORKL 2025-03-07
← Iranian "Dream Job" campaign report ORKL 2024-11-12
← When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors report ORKL 2024-03-13
← Staying ahead of threat actors in the age of AI report ORKL 2024-02-20
← Israel-Hamas War in Cyber February 2024 Tool of First Resort report ORKL 2024-02-08 Uses
→ Exfiltration Over C2 Channel technique ATT&CK mapping → Web Service technique ATT&CK mapping → Acquire Infrastructure: Domains technique ATT&CK mapping → User Execution: Malicious File technique ATT&CK mapping → Protocol Tunneling technique ATT&CK mapping → Phishing: Spearphishing via Service technique ATT&CK mapping → Establish Accounts: Social Media Accounts technique ATT&CK mapping T1585.001 ↗ inferred Establish Accounts: Social Media Accounts Resource Development fabricated recruiter personas on LinkedIn (Mandiant)
Regional co-occurrence · associated techniques Honesty note Regional co-occurrence is association, not prediction. These techniques appeared alongside UNC1549 / TA455's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Defensive coverage · Microsoft 365 Which Microsoft 365 controls protect , detect , or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 3 techniques
Advanced Anti-Phishing T1566 partial Anti-SpoofingT1566 significant Multifactor AuthenticationT1566 partial AntimalwareT1204 significant AntimalwareT1204.002 significant AntimalwareT1566 significant Anti-PhishingT1566 significant AntiSpamT1566 significant
detect · 4 techniques
Adaptive Application Control IntegrationT1204 partial Adaptive Application Control IntegrationT1204.002 partial Advanced Anti-Phishing T1566 partial App GovernanceT1566 significant Advanced Threat HuntingT1566 significant Preset Security PoliciesT1204 significant Preset Security PoliciesT1566 significant Safe AttachmentsT1204 significant Safe AttachmentsT1204.002 significant Safe AttachmentsT1566 significant ATT&CK Simulation TrainingT1204 partial ATT&CK Simulation TrainingT1204.002 partial ATT&CK Simulation TrainingT1566 partial Safe LinksT1204 significant Safe LinksT1566 significant Secure ScoreT1204 minimal Secure ScoreT1204.002 minimal Secure ScoreT1566 minimal Threat ExplorerT1566 partial Threat TrackerT1566 minimal Threat Protection Status ReportT1566 partial Continuous Access EvaluationT1585 significant Audit SolutionsT1566 partial
respond · 3 techniques
Advanced Anti-Phishing T1566 partial Automated Investigation and ResponseT1204.002 significant Automated Investigation and ResponseT1566 significant Incident ResponseT1566 minimal Quarantine PoliciesT1204 significant Quarantine PoliciesT1204.002 significant Quarantine PoliciesT1566 significant Safe AttachmentsT1204 significant Safe AttachmentsT1204.002 significant Safe AttachmentsT1566 significant ATT&CK Simulation TrainingT1204 partial ATT&CK Simulation TrainingT1204.002 partial ATT&CK Simulation TrainingT1566 partial
Countermeasures · D3FEND Defensive techniques that counter UNC1549 / TA455's TTPs, from MITRE D3FEND . The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.
Suggested · co-occurring (unverified)
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.
Malware NightLedger co-mentioned in 2 items Malware ArcBridge co-mentioned in 2 items Malware BridgeHead co-mentioned in 2 items Sector Aerospace/Telecom (implied by Mirage Kitten targeting) co-mentioned in 1 item Technique T1195 co-mentioned in 1 item Country Russia co-mentioned in 1 item Malware Creduz co-mentioned in 1 item Technique T1476 co-mentioned in 1 item Sector Diplomatic organizations co-mentioned in 1 item Malware MobiDash co-mentioned in 1 item Sector Public sector co-mentioned in 1 item Malware Anatsa co-mentioned in 1 item Zero Hour Auto PurgeT1204 significant
Zero Hour Auto PurgeT1204.002 significant
Zero Hour Auto PurgeT1566 significant
Malware Trojan-Dropper.AndroidOS.Banker co-mentioned in 1 item
Malware PowerCloud co-mentioned in 1 item
Technique T1204.002 co-mentioned in 1 item
Country Middle East (implied by Mirage Kitten's regional focus) co-mentioned in 1 item
Malware HiddenAd co-mentioned in 1 item
Malware Umbrij co-mentioned in 1 item
Technique T1528 co-mentioned in 1 item
Technique T1572 co-mentioned in 1 item
Sector Corporate email/communications co-mentioned in 1 item
Technique T1071 co-mentioned in 1 item
Malware Mamont co-mentioned in 1 item
Malware Cleanova loader co-mentioned in 1 item
Sector Financial (banking users) co-mentioned in 1 item
Country Belarus co-mentioned in 1 item
Technique T1090.003 co-mentioned in 1 item
Technique T1566 co-mentioned in 1 item
Country Tanzania co-mentioned in 1 item
Sector SMB co-mentioned in 1 item