• العربية
  • فارسی
Brand
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
  • Theme
  • Language
    • العربية
    • فارسی
  • Iran Insight
  • Politics
  • Economy
  • Analysis
  • Special Report
  • Opinion
  • Podcast
  • Live TV
All rights reserved for Volant Media UK Limited
volant media logo

Iran-linked hackers hit Mideast defense, space firms with new malware

Nov 19, 2025, 01:22 GMT+0Updated: 23:53 GMT+0
A computer keyboard lit by a displayed cyber code is seen in this illustration picture taken on March 1, 2017
A computer keyboard lit by a displayed cyber code is seen in this illustration picture taken on March 1, 2017

Google-owned security firm Mandiant reported on Tuesday that Iran-linked UNC1549 breached Middle East aerospace, aviation and defense organizations in a campaign from late 2023 to October 2025.

“The operation represents a notable technical advancement for the group, which introduced two previously undocumented custom backdoors: TWOSTROKE, a lightweight Windows implant written in C++ that supports command execution, file operations, screenshot capture and various persistence methods,” Google-owned firm said.

“The other is DEEPROOT, a cross-platform backdoor developed in ‘Go’ language crossed platform that works on both Linux and Windows systems, enabling shell commands and file transfers,” the report added.

Attackers gained initial access primarily through spear-phishing emails containing tailored job recruitment lures aimed at defense and aviation professionals, as well as through supply-chain compromises involving trusted third-party software vendors and virtual desktop infrastructure providers, Mandiant reported.

“Once inside victim networks, UNC1549 (aka Nimbus Manticore/Tropical Scorpius) deployed additional tools including SIGHTGRAB for screenshots and CRASHPAD for credential harvesting and data staging,” Mandiant said. “Command-and-control traffic was routed through compromised Microsoft Azure tenant accounts to blend with legitimate cloud activity and avoid detection.”

Mandiant said with high confidence that the activity supports Iranian state interests focused on strategic intelligence collection.

Sensitive data was exfiltrated from compromised networks, though the specific content and affected countries have not been disclosed.

Most Viewed

What Operation Economic Outcast means for Iran, and for everyone trading with
1
INSIGHT

What Operation Economic Outcast means for Iran, and for everyone trading with

2
INSIGHT

Iran shrugs off US economic war as analysts sound alarm

3

Tehran gas stations run dry as Iran’s fuel deficit bites

4
ANALYSIS

Iran keeps finding gas. Getting it out is the problem

5
INSIGHT

Who speaks for Iran? Rezaei’s threats fuels divide over war and diplomacy

Banner
Banner

Spotlight

  • Tehran debates waiting out Trump’s economic war
    INSIGHT

    Tehran debates waiting out Trump’s economic war

  • Will Mojtaba Khamenei's absence help the Islamic Republic survive?
    ANALYSIS

    Will Mojtaba Khamenei's absence help the Islamic Republic survive?

  • What Operation Economic Outcast means for Iran, and for everyone trading with
    INSIGHT

    What Operation Economic Outcast means for Iran, and for everyone trading with

  • Iran keeps finding gas. Getting it out is the problem
    ANALYSIS

    Iran keeps finding gas. Getting it out is the problem

  • Who speaks for Iran? Rezaei’s threats fuels divide over war and diplomacy
    INSIGHT

    Who speaks for Iran? Rezaei’s threats fuels divide over war and diplomacy

  • Tehran mosques used to surveil, shoot at January protesters
    EXCLUSIVE

    Tehran mosques used to surveil, shoot at January protesters

Banner