UNC1549, also tracked as Screening Serpens, Smoke Sandstorm, Nimbus Manticore, and Iranian Dream Job, is an Iran-linked cyberespionage threat group active since at least 2022 and assessed to operate in support of Iranian intelligence objectives aligned with IRGC strategic priorities. The group is known for highly tailored social-engineering campaigns, especially recruitment- and meeting-themed lures, used to compromise personnel in trusted or technically valuable roles and obtain long-term covert access for intelligence collection. The actor has targeted organizations and individuals associated with aerospace, defense, technology, satellite communications, research and development, telecommunications, and defense supply logistics. Reported victim geography includes the United States, Israel, the United Arab Emirates, the United Kingdom, France, Germany, and other Middle Eastern countries. Its operations emphasize persistence and stealth over immediate disruption, with the apparent objective of sustained internal access and collection of sensitive corporate and strategic information. UNC1549 commonly uses spearphishing as its primary initial-access vector and has deployed multiple remote-access trojan variants across related malware families including MiniBike, MiniBus, MiniUpdate, and MiniJunk V2. Observed tradecraft includes DLL sideloading, AppDomainManager hijacking in .NET applications, abuse of legitimate signed binaries, persistence via scheduled tasks and Registry Run keys, and encrypted command-and-control over cloud-hosted infrastructure. AppDomainManager hijacking has been used to force malicious code execution early in application startup and to weaken native telemetry or validation controls, improving defense evasion. The group has also rotated malware variants and command infrastructure rapidly while preserving core functionality, a pattern consistent with efforts to defeat signature-based detection. Capabilities attributed to the group include remote access, covert persistence, file collection and exfiltration, process control, shell execution, and broader post-compromise espionage activity. Stolen information has included internal correspondence, project documentation, and technical data relevant to targeted sectors. The actor is best characterized as an espionage-focused Iranian APT rather than a ransomware or extortion operation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using tailored recruitment-themed phishing lures to deploy remote-access tools against targets in the United States, Israel, the UAE, and other Middle East countries.
Iran-linked cyber-espionage group active since at least 2022, targeting aerospace, defense, technology, R&D, satellite communications, and defense logistics organizations via Dream Job-style spear-phishing to gain long-term covert access for intelligence collection.
Espionage campaigns using recruitment-themed social engineering, including tailored lures and new RAT variants, aligned with IRGC strategic priorities.
Iran-linked cyberespionage group conducting spear-phishing and social-engineering campaigns using fake job listings and spoofed meeting invitations to target aerospace, defense manufacturing, and telecommunications organizations. In 2026 it deployed MiniUpdate and MiniJunk V2 RAT variants and used AppDomainManager hijacking, ETW disabling, strong-name signature validation bypass, DLL sideloading, scheduled-task persistence, and Azure-hosted C2 infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.