Subtle Snail
Named by ProdaftSuspected state sponsor: Islamic Republic of IranSubtle Snail is PRODAFT's designation for an IRGC-linked Iranian espionage cluster overlapping with UNC1549 and Smoke Sandstorm, active since at least June 2022. The group targets European telecommunications companies alongside aerospace and defense organizations, having successfully compromised 34 devices across 11 organizations in the United States, Canada, France, the United Kingdom, and the UAE in a documented 2025 campaign. Initial access relies on LinkedIn-based social engineering where the group impersonates HR representatives from aerospace and defense companies to identify and contact key personnel before sending spear-phishing emails with fake interview links delivering malicious ZIP files. The core payload is a custom MINIBIKE backdoor variant communicated through Azure-proxied command and control infrastructure; unlike the Nimbus Manticore variant, Subtle Snail's version uses a simpler command set and less obfuscation, deploying victim-specific unique DLLs via sideloading for each action. The group systematically collects emails, VPN configurations, network documentation, and confidential shared files for long-term persistence and strategic intelligence exfiltration.
Targeted Regions
EuropeEurope
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Targeted Sectors
Recent Indexed Reports
Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.