Threats Tagged 'minibike'
View all threats tagged with 'minibike'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'minibike'
Click on any threat for detailed analysis and mitigation recommendations
UNC1549, an Iranian-linked threat group, has been targeting aerospace, aviation, and defense industries since mid-2024. They employ sophisticated initial access techniques, including exploiting third-party relationships and targeted phishing. The group uses custom malware like TWOSTROKE, LIGHTRAIL, and DEEPROOT for persistence, and tools like DCSYNCER.SLICK and CRASHPAD for privilege escalation. UNC1549 demonstrates advanced lateral movement, reconnaissance, and defense evasion tactics. They extensively use SSH reverse tunnels and Azure infrastructure for command and control. The group's primary objective appears to be espionage, focusing on data collection and leveraging compromised organizations to target others in the same sector. Join the discussion | AlienVault OTX General | 11/18/2025, 02:11:13 UTC Added: 11/18/2025, 02:22:52 UTC |
The UNK_SmudgedSerpent threat actor, likely linked to Iranian espionage efforts, targeted academics and foreign policy experts from June to August 2025 using phishing campaigns with domestic political and health-related lures. The actor employed Remote Management & Monitoring (RMM) tools and credential harvesting techniques, showing overlapping tactics with known Iranian groups such as TA455, TA453, and TA450. Although attribution is not definitive, the targeting aligns with Iranian intelligence priorities, focusing on sensitive policy and academic sectors. The campaign's medium severity reflects moderate impact potential without known exploits in the wild. European organizations involved in foreign policy, academia, and research are at risk, especially in countries with strong diplomatic ties or geopolitical interest in Iran. Mitigation requires targeted user awareness, strict monitoring of RMM tool usage, and enhanced email filtering tuned to political and health-themed lures. Countries like Germany, France, the UK, Italy, and the Netherlands are most likely affected due to their active academic communities and diplomatic engagement with Iran. The threat's medium severity is due to its espionage focus, moderate ease of exploitation via phishing, and the absence of widespread destructive payloads or zero-day exploits. Defenders should prioritize detection of credential harvesting and suspicious RMM activity while maintaining vigilance for evolving Iranian espionage tactics. Join the discussion | AlienVault OTX General | 11/05/2025, 19:04:52 UTC Added: 11/05/2025, 21:52:26 UTC |
Showing 1 to 2 of 2 results