UNC1549 (Screening Serpens / Nimbus Manticore)
Iranian state-sponsored (IRGC-linked) · Espionage / intelligence collection / aerospace and defence intelligence
Tactics, Techniques & Procedures (TTPs)
- Career-themed spear-phishing with fake job offers from defence industry personas ("Iranian Dream Job" methodology)
- MiniFast backdoor — LLM-assisted rapid development enabling fast malware iteration
- AppDomain Hijacking for stealthy .NET code injection: replaces legacy DLL sideloading, executes before EDR initialises
- SEO poisoning for malware delivery — trojanised legitimate software installers (Oracle SQL Developer lure documented)
- DLL sideloading alongside legitimate signed executables (legacy delivery, still observed)
- Credential collection, file staging, and persistent remote command execution via backdoor
- Azure-hosted C2 infrastructure with dedicated per-target domain clusters
Known Targets
Analyst Notes
Mandiant tracking designation UNC1549, corresponding to Palo Alto Unit 42's Screening Serpens and the Nimbus Manticore designation used in other published research. Assessed as IRGC-linked based on targeting priorities and operational patterns. Historically focused on aerospace and defence intelligence across Israel, the Gulf states, and Turkey. Following the US-Iran regional conflict escalation beginning 28 February 2026 (Operation Epic Fury), the group dramatically increased operational tempo: new backdoor family (MiniFast), two new delivery techniques (AppDomain Hijacking, SEO poisoning), and significantly expanded European targeting within a three-month window. The SEO poisoning delivery channel is particularly significant — it bypasses email security controls entirely, requiring no prior contact with the target. LLM-assisted malware development (MiniFast) indicates adaptation of commercial AI tools to accelerate retooling under operational pressure.
Also Known As