[threat-actors] Add UNC1549

This commit is contained in:
Mathieu4141 2024-02-29 10:38:27 -08:00
parent 7b3c8a87c3
commit cc68b22fe2

View file

@ -15290,6 +15290,17 @@
}, },
"uuid": "0e3224a0-3544-47d7-b1ce-fb3eb21286ad", "uuid": "0e3224a0-3544-47d7-b1ce-fb3eb21286ad",
"value": "UAC-0184" "value": "UAC-0184"
},
{
"description": "UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.",
"meta": {
"country": "IR",
"refs": [
"https://www.mandiant.com/resources/blog/suspected-iranian-unc1549-targets-israel-middle-east"
]
},
"uuid": "a2a7d49f-f517-4eeb-9ec8-b9b74e3fe756",
"value": "UNC1549"
} }
], ],
"version": 302 "version": 302