UNC6446 is an Iranian-nexus threat actor associated with espionage-oriented targeting of the aerospace and defense sectors. The group has been reported targeting organizations and personnel in the United States and the Middle East, with a particular emphasis on abusing recruitment and hiring workflows as an intrusion vector. Its tradecraft includes the use of malicious resume-builder and personality-test applications to deliver custom malware to intended victims, as well as broader phishing and information-theft activity. UNC6446 has also been cited among Iran-linked actors conducting exploitation of public-facing servers and credential- or data-focused operations against Israeli, U.S., and regional networks. The actor fits a broader pattern of Iranian state-aligned cyber activity focused on defense-industrial intelligence collection and access development through social engineering and malware delivery.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named activity cluster participating in phishing, data theft, and server exploitation in the context of the regional hybrid conflict.
Named as part of the pre-existing APT landscape active prior to Feb 28; associated activity described as phishing, exploitation of public servers, and information theft targeting Israeli, US, and regional networks.
Named activity cluster referenced in Iran-linked pre-conflict cyber operations targeting Israeli, US, and regional networks.
Iran-linked cluster described as abusing hiring workflows (resume apps) to deliver malware to aerospace and defense targets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.