An Iran-linked threat actor known as UNC1549 has been attributed to a new espionage campaign targeting aerospace, aviation, and defense industries in the Middle East, including Israel and the U.A.E.
According to researchers from the threat intelligence firm Mandiant, the other targets of the cyber espionage activity likely include Turkey, India, and Albania.
UNC1549 is said to overlap with Smoke Sandstorm (previously Bohrium) and Crimson Sandstorm (previously Curium), the latter of which is an Islamic Revolutionary Guard Corps (IRGC) affiliated group also known as Imperial Kitten, TA456, Tortoiseshell, and Yellow Liderc.
This suspected UNC1549 activity has been active since at least June 2022 and is still ongoing as of February 2024.
According to the report, the hackers targeted employees within the aviation and defense sectors with fake job offers for tech and defense-related positions – specifically, for people who work with thermal imaging.
The attacks make use of Microsoft Azure cloud infrastructure for command-and-control (C2) and social engineering involving job-related lures to deliver two backdoors dubbed MINIBIKE and MINIBUS.
The spear-phishing emails are designed to disseminate links to fake websites containing Israel-Hamas related content or phony job offers, resulting in the deployment of a malicious payload. Bogus login pages mimicking major companies to harvest credentials are also found.
The custom backdoors, upon establishing C2 access, act as a conduit for intelligence collection and for further access into the targeted network. Another tool deployed at this stage is a tunneling software called LIGHTRAIL that communicates using Azure cloud.
While MINIBIKE is based in C++ and capable of file exfiltration and upload, and command execution, MINIBUS serves as a more “robust successor” with enhanced reconnaissance features.
The evasion methods deployed in this campaign, namely the tailored job-themed lures combined with the use of cloud infrastructure for C2, may make it challenging for network defenders to prevent, detect, and mitigate this activity.
















Comments