mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-26 08:47:18 +00:00
[threat-actors] Add UNC1549
This commit is contained in:
parent
7b3c8a87c3
commit
cc68b22fe2
1 changed files with 11 additions and 0 deletions
|
@ -15290,6 +15290,17 @@
|
||||||
},
|
},
|
||||||
"uuid": "0e3224a0-3544-47d7-b1ce-fb3eb21286ad",
|
"uuid": "0e3224a0-3544-47d7-b1ce-fb3eb21286ad",
|
||||||
"value": "UAC-0184"
|
"value": "UAC-0184"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"description": "UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.",
|
||||||
|
"meta": {
|
||||||
|
"country": "IR",
|
||||||
|
"refs": [
|
||||||
|
"https://www.mandiant.com/resources/blog/suspected-iranian-unc1549-targets-israel-middle-east"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"uuid": "a2a7d49f-f517-4eeb-9ec8-b9b74e3fe756",
|
||||||
|
"value": "UNC1549"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"version": 302
|
"version": 302
|
||||||
|
|
Loading…
Reference in a new issue