Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks post, november 18, 2025november 28, 2025 Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued attacks aimed at aerospace, aviation, and defense industries in the Middle East. The activity has been attributed by Google-owned Mandiant to a threat cluster tracked as UNC1549 (aka GalaxyGato, Nimbus Manticore, or Subtle Snail), which was first documented by the threat intelligence firm early last year. Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks: Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks malware 2025