Skip to content
← All Threat Actors
Nation-State high Iran

UNC1549 (Screening Serpens / Nimbus Manticore)

Iranian state-sponsored (IRGC-linked) · Espionage / intelligence collection / aerospace and defence intelligence

Reports 1
Active Since 2022
Last Reported 4 Jun 2026
Sectors Targeted defence, critical-infrastructure, communications

Tactics, Techniques & Procedures (TTPs)

  • Career-themed spear-phishing with fake job offers from defence industry personas ("Iranian Dream Job" methodology)
  • MiniFast backdoor — LLM-assisted rapid development enabling fast malware iteration
  • AppDomain Hijacking for stealthy .NET code injection: replaces legacy DLL sideloading, executes before EDR initialises
  • SEO poisoning for malware delivery — trojanised legitimate software installers (Oracle SQL Developer lure documented)
  • DLL sideloading alongside legitimate signed executables (legacy delivery, still observed)
  • Credential collection, file staging, and persistent remote command execution via backdoor
  • Azure-hosted C2 infrastructure with dedicated per-target domain clusters

Known Targets

European aviation operators (carriers, MRO providers, air traffic control)Western European telecommunications operatorsAerospace and defence contractors and supply chainIsraeli defence and critical infrastructureGulf state organisations (UAE, Saudi Arabia)Turkish aerospace and government entities

Analyst Notes

Mandiant tracking designation UNC1549, corresponding to Palo Alto Unit 42's Screening Serpens and the Nimbus Manticore designation used in other published research. Assessed as IRGC-linked based on targeting priorities and operational patterns. Historically focused on aerospace and defence intelligence across Israel, the Gulf states, and Turkey. Following the US-Iran regional conflict escalation beginning 28 February 2026 (Operation Epic Fury), the group dramatically increased operational tempo: new backdoor family (MiniFast), two new delivery techniques (AppDomain Hijacking, SEO poisoning), and significantly expanded European targeting within a three-month window. The SEO poisoning delivery channel is particularly significant — it bypasses email security controls entirely, requiring no prior contact with the target. LLM-assisted malware development (MiniFast) indicates adaptation of commercial AI tools to accelerate retooling under operational pressure.

Also Known As

Screening SerpensNimbus ManticoreSmoke Sandstorm (shared infrastructure and tradecraft)