Actors Insights|Latest update04/07/2026

Subtle Snail

Named by ProdaftSuspected state sponsor: Islamic Republic of Iran

Subtle Snail is PRODAFT's designation for an IRGC-linked Iranian espionage cluster overlapping with UNC1549 and Smoke Sandstorm, active since at least June 2022. The group targets European telecommunications companies alongside aerospace and defense organizations, having successfully compromised 34 devices across 11 organizations in the United States, Canada, France, the United Kingdom, and the UAE in a documented 2025 campaign. Initial access relies on LinkedIn-based social engineering where the group impersonates HR representatives from aerospace and defense companies to identify and contact key personnel before sending spear-phishing emails with fake interview links delivering malicious ZIP files. The core payload is a custom MINIBIKE backdoor variant communicated through Azure-proxied command and control infrastructure; unlike the Nimbus Manticore variant, Subtle Snail's version uses a simpler command set and less obfuscation, deploying victim-specific unique DLLs via sideloading for each action. The group systematically collects emails, VPN configurations, network documentation, and confidential shared files for long-term persistence and strategic intelligence exfiltration.

First Seen:Jan 2025
Last Seen:Sep 2025
Indexed Reports:1
Public IOCs:8
Cluster: Unclassified
also known as:
Subtle Snail

Targeted Regions

Europe
EU
Europe
Europe
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025 ~ Sep 2025
Jan 2025Dec 2026

Targeted Sectors

DefenseAerospaceTelecommunication

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.