SYMBOLCOMMON_NAMEaka. SYNONYMS

UNC1549  (Back to overview)

aka: Nimbus Manticore

UNC1549 is an Iranian threat actor linked to Tortoiseshell and potentially the IRGC. They have been active since at least June 2022, targeting entities worldwide with a focus on the Middle East. UNC1549 uses spear-phishing and credential harvesting for initial access, deploying custom malware like MINIBIKE and MINIBUS backdoors. They have also been observed using evasion techniques and a tunneler named LIGHTRAIL in their operations.


Associated Families
win.minifast

References
2026-06-01Nextron SystemsJonathan Peters
Detecting Nimbus Manticore and their sideloading infection chains
MiniFast
2026-05-22Check PointCheckpoint Research
Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict
MiniFast
2025-09-22Check Point ResearchCheck Point Research
Iranian Threat Actor Nimbus Manticore Expands Campaigns into Europe with Advanced Malware and Fake Job Lures
MINIBIKE MiniJunk UNC1549
2025-09-22Check Point ResearchCheck Point Research
Nimbus Manticore Deploys New Malware Targeting Europe
MINIBIKE MiniJunk UNC1549
2024-02-27MandiantChen Evgi, Jonathan Leathery, Ofir Rozmann
When Cats Fly: Suspected Iranian Threat Actor UNC1549 Targets Israeli and Middle East Aerospace and Defense Sectors
LIGHTRAIL MINIBIKE MINIBUS UNC1549

Credits: MISP Project