UNC1549 TTPs: Iranian APT Targeting Aerospace and Defense

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

UNC1549 TTPs: Iranian APT Targeting Aerospace and Defense

Overview

UNC1549 is an Iranian-linked cyber-espionage group active since at least June 2022. It targets aerospace, aviation, and defense organizations across the Middle East, South Asia, and Western Europe. The group deploys custom malware, uses fake React-based career portals to deliver multi-stage payloads, and exfiltrates data over encrypted C2 channels.

Article Link: UNC1549 TTPs: Iranian APT Targeting Aerospace and Defense

1 post - 1 participant

Read full topic



Malware Analysis, News and Indicators - Latest topics
Next Post Previous Post