{"id":852,"date":"2025-11-18T15:30:53","date_gmt":"2025-11-18T13:30:53","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=852"},"modified":"2025-11-28T15:32:23","modified_gmt":"2025-11-28T13:32:23","slug":"iranian-hackers-use-deeproot-and-twostroke-malware-in-aerospace-and-defense-attacks","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/11\/18\/iranian-hackers-use-deeproot-and-twostroke-malware-in-aerospace-and-defense-attacks\/","title":{"rendered":"Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued attacks aimed at aerospace, aviation, and defense industries in the Middle East.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The activity has been attributed by Google-owned Mandiant to a threat cluster tracked as&nbsp;<strong><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/analysis-of-unc1549-ttps-targeting-aerospace-defense\" rel=\"noreferrer noopener\" target=\"_blank\">UNC1549<\/a><\/strong>&nbsp;(aka GalaxyGato, Nimbus Manticore, or Subtle Snail), which was&nbsp;<a href=\"https:\/\/thehackernews.com\/2024\/02\/iran-linked-unc1549-hackers-target.html\" rel=\"noreferrer noopener\" target=\"_blank\">first documented<\/a>&nbsp;by the threat intelligence firm early last year.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/11\/18\/iranian-hackers-use-deeproot-and-twostroke-malware-in-aerospace-and-defense-attacks\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2025\/11\/iranian-hackers-use-deeproot-and.html\">Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks<\/a><span class=\"screen-reader-text\">: Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued attacks aimed at aerospace, aviation, and defense industries in the Middle East. The activity has been attributed by Google-owned Mandiant to a threat cluster tracked as&nbsp;UNC1549&nbsp;(aka GalaxyGato, Nimbus Manticore, or Subtle&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[40],"class_list":["post-852","post","type-post","status-publish","format-standard","hentry","category-malware","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/852","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=852"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/852\/revisions"}],"predecessor-version":[{"id":853,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/852\/revisions\/853"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=852"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=852"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=852"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}