Screening Serpens, also tracked as UNC1549 and Smoke Sandstorm and associated with Iranian Dream Job campaigns, is an Iran-linked advanced persistent threat group active since at least 2022. Its operations support Iranian intelligence objectives through cyberespionage and covert access to corporate networks. Principal targets include technology companies, aerospace organizations, defense contractors, and telecommunications providers, including organizations involved in research and development, satellite communications, and defense logistics. Its targeting spans the United States, Israel, the United Arab Emirates, other Middle Eastern countries, and Western Europe. The group uses highly personalized spear-phishing and social engineering, particularly recruitment-themed lures and spoofed video-conferencing invitations. Victims are induced to execute malicious archives or installers impersonating trusted corporate services. Infection chains combine DLL sideloading with AppDomainManager hijacking to execute malicious code during legitimate .NET application initialization. Associated evasion techniques include disabling Event Tracing for Windows, bypassing strong-name validation, code obfuscation, junk-code inflation, and delayed execution. Persistence is established through scheduled tasks and Registry Run Keys. Between February and April 2026, Screening Serpens deployed six newly identified remote-access Trojan variants across the MiniUpdate and MiniJunk V2 families. These implants support command execution, file manipulation, process control, and data exfiltration, including chunked file transfers. The group predominantly uses Azure-hosted HTTPS command-and-control infrastructure, assigning separate infrastructure to individual targets and malware variants and rotating domains and command mappings between deployments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Iranian threat group discussed as a tradecraft comparison, not as the attributed operator of Blinder Tunnel. It targets technology, aerospace and defense professionals in the Middle East using personalized recruitment lures and AppDomainManager hijacking.
Iranian intelligence-linked cyber-espionage cluster conducting coordinated campaigns using MiniUpdate and MiniJunk V2 RATs for persistent access and confidential-data collection. It uses recruitment-themed spear-phishing, DLL sideloading, AppDomainManager hijacking, Azure-hosted and per-campaign segmented C2 infrastructure, and web-based exfiltration.
Using tailored recruitment-themed phishing lures to deploy remote-access tools against targets in the United States, Israel, the UAE, and other Middle East countries.
Iran-linked cyber-espionage group active since at least 2022, targeting aerospace, defense, technology, R&D, satellite communications, and defense logistics organizations via Dream Job-style spear-phishing to gain long-term covert access for intelligence collection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.