Subtle Snail
Subtle Snail is an Iranian cyber-espionage group. Reporting cited in the provided content describes it as a separate cluster of activity with connections to Iran and as an espionage group believed to be a smaller cluster within the broader Charming Kitten operation. It has also been referenced as UNC1549 in the provided material. Subtle Snail has targeted employees of EU telecommunications and defense organizations using fake LinkedIn job lures. PRODAFT reported that this activity infected 34 devices across 11 organizations. The group’s activity broadly aligns with TTPs seen in Nimbus Manticore operations, but is differentiated by its malware capabilities, command-and-control infrastructure, and targeting preferences. A related cluster linked to Subtle Snail uses simpler payloads such as dxgi.dll, which shares code similarities with MiniJunk but lacks the more sophisticated obfuscation seen in that malware.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Associated malware families
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage group referenced as linked to a separate cluster using simpler payloads such as dxgi.dll that share code similarities with MiniJunk.
A separate Iran-linked espionage cluster discussed as related but distinct from Nimbus Manticore, sharing broadly similar TTPs while differing in malware capabilities, C2 infrastructure, and targeting preferences.
Iranian cyber-espionage cluster using fake LinkedIn job lures to target EU telecom and defense personnel; assessed as a smaller cluster within Charming Kitten; infections reported across multiple organizations/devices.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.