The Containment Era is here. →Explore

Executive Summary

In late 2025, an Iranian-linked threat group known as UNC1549 targeted aerospace and defense organizations in the Middle East, deploying custom backdoors named TWOSTROKE and DEEPROOT. The attackers gained access through spear-phishing and strategic web compromises, establishing persistent footholds and enabling sustained espionage operations. Google-owned Mandiant attributed the campaign to advanced initial access and lateral movement techniques, allowing the threat actors to blend into legitimate network activity while exfiltrating sensitive intellectual property and operational data. The campaign underscored weaknesses in internal segmentation, encrypted traffic oversight, and anomaly detection within high-value verticals.

This incident highlights an uptick in sophisticated espionage attacks on critical infrastructure using tailored malware and stealthy, post-compromise tactics. The use of novel backdoors and multi-stage intrusion campaigns demonstrates an evolving threat landscape, emphasizing the need for deeper defense in depth and zero trust approaches among organizations handling sensitive data.

Why This Matters Now

Aerospace and defense organizations remain top targets for nation-state actors leveraging custom malware and advanced evasion tactics. As similar campaigns proliferate, urgency grows for organizations to adopt robust segmentation, east-west visibility, and proactive anomaly detection to counter persistent lateral threats poised to exploit gaps in hybrid and multicloud environments.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Weak segmentation and lack of east-west traffic controls allowed lateral movement, indicating gaps relative to NIST 800-53 and Zero Trust mandates.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying CNSF Zero Trust controls such as segmentation, microsegmentation, east-west inspection, advanced egress filtering, inline IPS, and encrypted traffic enforcement would have significantly constrained adversary movement, data theft, and command channels across the cloud estate.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Centralized visibility would have detected suspicious new workload activity.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Lateral privilege escalation would be contained to the compromised segment.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Suspicious internal movement and service access would be blocked or flagged.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: C2 traffic signatures and malicious payloads would be detected or blocked.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts to unapproved destinations would be blocked.

Impact (Mitigations)

Anomalies in usage and access are rapidly detected and escalated for response.

Impact at a Glance

Affected Business Functions

  • Research and Development
  • Intellectual Property Management
  • Supply Chain Operations
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Potential exposure of sensitive technical data, including proprietary designs and strategic plans, leading to competitive disadvantage and regulatory scrutiny.

Recommended Actions

  • Implement Zero Trust Segmentation and east-west traffic controls to contain adversary lateral movement.
  • Enforce strict egress policy with FQDN filtering and encrypted traffic inspection to block exfiltration and C2.
  • Expand centralized multicloud visibility to monitor, baseline, and rapidly investigate anomalous traffic flows.
  • Deploy inline IPS and continuous anomaly detection across cloud environments for real-time adversary disruption.
  • Regularly audit access controls and privilege assignments for least privilege enforcement and rapid misconfiguration remediation.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image