National Cyber Warfare Foundation (NCWF)

Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks


0 user ratings
2025-11-18 15:36:24
milo
Attacks
Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued attacks aimed at aerospace, aviation, and defense industries in the Middle East.
The activity has been attributed by Google-owned Mandiant to a threat cluster tracked as UNC1549 (aka Nimbus Manticore or Subtle Snail), which was first documented by the threat



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/11/iranian-hackers-use-deeproot-and.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.