{"id":8527,"date":"2025-11-18T10:03:32","date_gmt":"2025-11-18T10:03:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/18\/unc1549-hackers-with-custom-tools-attacking-aerospace-and-defense-systems-to-steal-logins\/"},"modified":"2025-11-18T10:03:32","modified_gmt":"2025-11-18T10:03:32","slug":"unc1549-hackers-with-custom-tools-attacking-aerospace-and-defense-systems-to-steal-logins","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/18\/unc1549-hackers-with-custom-tools-attacking-aerospace-and-defense-systems-to-steal-logins\/","title":{"rendered":"UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins"},"content":{"rendered":"<p>    UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Since mid-2024, a sophisticated Iranian-backed threat group known as UNC1549 has been conducting targeted campaigns against aerospace, aviation, and defense organizations across the globe.<\/p>\n<p>The hackers employ an advanced dual approach, combining carefully crafted phishing campaigns with the exploitation of trusted connections between primary targets and their third-party suppliers.<\/p>\n<p>This strategy proves particularly effective against well-defended organizations like defense contractors, which often leave their vendors as softer targets for initial compromise.<\/p>\n<p>The threat group\u2019s operational methods demonstrate significant evolution and tactical sophistication. Operating from late 2023 through 2025, UNC1549 leverages highly targeted, role-relevant <a href=\"https:\/\/cybersecuritynews.com\/hr-it-related-phishing-emails-are-top-clicked\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing emails<\/a> to establish initial footholds.<\/p>\n<p>Once inside a network, they employ creative lateral movement techniques, including stealing victim source code to craft spear-phishing campaigns using lookalike domains that bypass <a href=\"https:\/\/cybersecuritynews.com\/how-safe-are-isp-proxies-security-and-privacy-breakdown\/\" target=\"_blank\" rel=\"noreferrer noopener\">security proxies<\/a>.<\/p>\n<p>The group also abuses internal service ticketing systems to harvest credentials from unsuspecting employees.<\/p>\n<p>Google Cloud security analysts <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/analysis-of-unc1549-ttps-targeting-aerospace-defense\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that UNC1549 deploys custom tooling designed specifically to evade detection and complicate forensic investigations.<\/p>\n<p>Notably, every post-exploitation payload identified during investigations carried a unique hash, even when multiple samples of the same backdoor variant appeared within a single victim network.<\/p>\n<p>This level of customization underscores the group\u2019s substantial resources and commitment to operational security.<\/p>\n<p>One of the most technically significant aspects of UNC1549\u2019s operations involves their use of search order hijacking for malware persistence.<\/p>\n<p>This technique involves placing malicious DLLs within <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-exploiting-legitimate-software\/\" target=\"_blank\" rel=\"noreferrer noopener\">legitimate software<\/a> installation directories, allowing attackers to achieve persistent execution when administrators or users run the legitimate software.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjiV8g-rpbyApqUrMmCHUaLRf36OViEWk8uueP3qVcbEKmGBcCRUROd0ax5wODlAkFskrdZowjCgG9fTzFMjeMU-4VdQiRoB-lIaDZkxFI-LTAfS0IRzkZ65kxNLxNUOweKLnOy-1E-Moaj7Eoe4khv6tJE6mglrx4gjh2Z4zRmAiijoGfnTOJSq3_QGK8\/s16000\/Phishing%2520email%2520sent%2520by%2520UNC1549%2520%28Source%2520-%2520Google%2520Cloud%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing email sent by UNC1549 (Source \u2013 Google Cloud)<\/figcaption><\/figure>\n<\/div>\n<p>The group has successfully exploited this vulnerability in widely-used enterprise solutions, including FortiGate, VMWare, Citrix, Microsoft, and NVIDIA executables.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-initial-access\"><strong>Initial access<\/strong><\/h2>\n<p>In these cases, researchers detected that UNC1549 deliberately installed legitimate software after gaining initial access, specifically to abuse this DLL search order hijacking capability.<\/p>\n<p>The TWOSTROKE backdoor exemplifies this technical sophistication. This custom C++ backdoor communicates through SSL-encrypted TCP connections on port 443, making it difficult to distinguish from legitimate traffic.<\/p>\n<p>Upon execution, TWOSTROKE generates a unique victim identifier by retrieving the fully qualified DNS computer name using the Windows API function GetComputerNameExW(ComputerNameDnsFullyQualified).<\/p>\n<p>This name undergoes XOR encryption using a static key, converts to lowercase hexadecimal, and extracts the first eight characters before reversing them to create the bot ID.<\/p>\n<p>TWOSTROKE\u2019s command set enables extensive post-compromise capabilities, including system information collection, dynamic DLL loading, file manipulation, and persistent backdoor functionality.<\/p>\n<p>The malware receives hex-encoded payloads from command servers containing multiple commands separated by \u201c@##@\u201d delimiters. Commands range from file uploads and shell command execution to directory listing and file deletion operations.<\/p>\n<p>UNC1549\u2019s campaign prioritizes long-term <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> and anticipates investigator response. They strategically deploy backdoors that remain dormant for months, activating only after victims attempt remediation.<\/p>\n<p>This approach, combined with extensive reverse SSH shell usage and <a href=\"https:\/\/cybersecuritynews.com\/pypi-to-block-domains-resurrection-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">domains<\/a> mimicking victim industries, creates a challenging operational environment for defenders.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/unc1549-hackers-with-custom-tools\/\">UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/unc1549-hackers-with-custom-tools\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>UNC1549 Hackers with Custom Tools Attacking Aerospace and Defense Systems to Steal Logins Since mid-2024, a sophisticated Iranian-backed threat group known as UNC1549 has been conducting targeted campaigns against aerospace, aviation, and defense organizations across the globe. The hackers employ an advanced dual approach, combining carefully crafted phishing campaigns with the exploitation of trusted connections [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8527","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8527"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8527"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8527\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8527"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}