Subtle Snail is an Iranian cyber-espionage cluster associated with UNC1549 and assessed to operate within or alongside the broader Charming Kitten and Nimbus Manticore ecosystem. The group has targeted employees of European telecommunications and defense organizations using fake job and recruiter lures, including fraudulent LinkedIn-style employment approaches, to gain initial access for intelligence collection. The cluster is distinguished from related Iranian activity by its simpler malware tooling and somewhat different targeting preferences, despite overlapping tradecraft and development characteristics. Reported operations used spear-phishing and fake career portals to deliver malware, followed by DLL sideloading and deployment of a backdoor implemented as a malicious DLL. Its malware shares code similarities with MiniJunk, suggesting shared developers, shared tooling, or parallel operational support inside a larger Iranian intrusion framework. Subtle Snail’s observed capabilities support espionage objectives rather than disruptive or financially motivated operations. The group has demonstrated initial access via social-engineering lures, defense evasion through DLL sideloading, persistence and post-compromise malware execution, and data theft consistent with credential and intelligence collection. Available reporting characterizes it as a smaller Iranian espionage cluster focused on high-value sectors aligned with state intelligence priorities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage group referenced as linked to a separate cluster using simpler payloads such as dxgi.dll that share code similarities with MiniJunk.
A separate Iran-linked espionage cluster discussed as related but distinct from Nimbus Manticore, sharing broadly similar TTPs while differing in malware capabilities, C2 infrastructure, and targeting preferences.
Iranian cyber-espionage cluster using fake LinkedIn job lures to target EU telecom and defense personnel; assessed as a smaller cluster within Charming Kitten; infections reported across multiple organizations/devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.