2026-09-02NOTABLEAn Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding challenge
Screening Serpens
actor · actor:screening-serpens-unc1549-smoke-sandstorm-nimbus-manticore-iran-apt single-source
Iranian APT operationalising AppDomainManager hijacking; deployed six new RAT variants (MiniUpdate / MiniJunk V2) between February and April 2026. Kaspersky, which tracks the group as Mirage Kitten and states that equivalence itself, describes it as focused on aerospace, aviation, defence and telecommunications espionage across the Middle East and Africa, and in July 2026 documented a new toolset comprising the NightLedger backdoor and the BridgeHead and ArcBridge WebSocket tunnelers (Kaspersky Securelist, 2026-07-28).
Aliases: UNC1549, Smoke Sandstorm, Nimbus Manticore, Mirage Kitten
Coverage
4
first 2026-05-23 → last 2026-09-02
Latest activity
2026-09-02
An Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding…
Peak priority
high
2 high · 2 notable
Targets
telco
sectors: telco, aviation, finance · regions: middle-east, africa, europe
Sources cited
8
7 hosts
2026-05-234 appearances2026-09-02
Defender insights
What each entry about Screening Serpens tells a defender to do, newest first.
Triage · detection
Triage
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
uses
- ArcBridgeKaspersky: another WebSocket tunneling tool developed and used by the group, first identified April 2026
- BridgeHead
- NightLedgerKaspersky attributes NightLedger to the group on code and behavioural similarity to its historical implants
- Nimbus Manticore reverse SSH tunnelerGroup-IB attributes the reverse SSH tunneler to the same actor and infrastructure cluster as the TWOSTROKE-like backdoor (Group-IB, 2026-08-26).
- NodeRabbitKaspersky attributes NodeRabbit to Mirage Kitten with high confidence based on victimology, infrastructure patterns and delivery tradecraft.
- PollCatKaspersky attributes PollCat to Mirage Kitten based on structural similarity to the Retrograde/MiniFast backdoor and consistent victimology.
- TWOSTROKE(-like) backdoorGroup-IB attributes the TWOSTROKE-like backdoor to Nimbus Manticore/Tortoiseshell based on toolset and infrastructure analysis (Group-IB, 2026-08-26).
Story timeline
- 2026-09-02Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments
- 2026-08-28Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and Belarus
- 2026-07-29Mirage Kitten (UNC1549) fields the NightLedger backdoor and two WebSocket tunnelers, one of them built to negotiate through corporate proxies with the victim's own SSO
- 2026-05-23Unit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six new RATs
Hunting pivots
Affected products
ATT&CK techniques (21 across 9 tactics)
21 techniques observed across 4 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissancePhishing for Information: Spearphishing Link
- Initial AccessPhishing: Spearphishing via Service
- ExecutionScheduled Task/Job: Cron · Scheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: JavaScript · User Execution: Malicious File · Hijack Execution Flow: DLL · Hijack Execution Flow: Path Interception by Search Order Hijacking · Hijack Execution Flow: AppDomainManager
- PersistenceScheduled Task/Job: Cron · Scheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationScheduled Task/Job: Cron · Scheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information · Virtualization/Sandbox Evasion · Hijack Execution Flow: DLL · Hijack Execution Flow: Path Interception by Search Order Hijacking · Hijack Execution Flow: AppDomainManager
- DiscoverySystem Network Configuration Discovery · Process Discovery · System Information Discovery · Virtualization/Sandbox Evasion
- CollectionScreen Capture · Email Collection: Local Email Collection
- Command and ControlApplication Layer Protocol: Web Protocols · Proxy · Protocol Tunneling · Encrypted Channel: Symmetric Cryptography
Reconnaissance TA0043
T1598.003Phishing for Information: Spearphishing Link×1
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages.
Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
Initial Access TA0001
T1566.003Phishing: Spearphishing via Service×1
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
Execution TA0002
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
T1053.005Scheduled Task/Job: Scheduled Task×2
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×3
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1574.008Hijack Execution Flow: Path Interception by Search Order Hijacking×1
Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program.
Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1574.014Hijack Execution Flow: AppDomainManager×1
Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.
Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
Persistence TA0003
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
T1053.005Scheduled Task/Job: Scheduled Task×2
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
Privilege Escalation TA0004
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
T1053.005Scheduled Task/Job: Scheduled Task×2
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×2
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · ATT&CK page ↗
T1497Virtualization/Sandbox Evasion×1
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×3
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1574.008Hijack Execution Flow: Path Interception by Search Order Hijacking×1
Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program.
Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
T1574.014Hijack Execution Flow: AppDomainManager×1
Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.
Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗
Discovery TA0007
T1016System Network Configuration Discovery×1
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.
Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1497Virtualization/Sandbox Evasion×1
Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
Collection TA0009
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1114.001Email Collection: Local Email Collection×1
Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×3
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1090Proxy×2
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.
Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1572Protocol Tunneling×2
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗
T1573.001Encrypted Channel: Symmetric Cryptography×1
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.
Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗
Entries about Screening Serpens (4)
Earlier coverage (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- ArcBridge×2
- BridgeHead×2
- NightLedger×2
- Microsoft Windows×1
- Nimbus Manticore reverse SSH tunneler×1
- NodeRabbit×1
- PollCat×1
- TWOSTROKE(-like) backdoor×1
Where this entity is cited
Source distribution
- securelist.com2 (25%)
- cybersecuritydive.com1 (12%)
- group-ib.com1 (12%)
- research.checkpoint.com1 (12%)
- thehackernews.com1 (12%)
- therecord.media1 (12%)
- unit42.paloaltonetworks.com1 (12%)
All cited sources (8)
- cybersecuritydive.comCybersecurity Divehttps://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/
- group-ib.comGroup-IBhttps://www.group-ib.com/blog/tortoiseshell-apt-toolset-infrastructure/
- research.checkpoint.comCheck Point Research, 2026-05-22https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/
- securelist.comKaspersky Securelist (GReAT)https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
- securelist.comKaspersky Securelist (GReAT)https://securelist.com/mirage-kitten-new-tools/120811/
- thehackernews.comThe Hacker News, 2026-05-26https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html
- therecord.mediaThe Record (Recorded Future News)https://therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware
- unit42.paloaltonetworks.comUnit 42https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/