Iranian Hackers Accelerate MiniFast and MiniJunk V2 Deployment through Phishing and SEO Poisoning
Recent developments in cyber warfare have seen the Iranian state-sponsored group known as Nimbus Manticore, also referred to as Screening Serpens and UNC1549, intensifying its operations. Following a joint U.S.-Israeli military campaign against Iran in late February 2026, the group has launched a series of sophisticated attacks targeting organizations in the aviation and software sectors across the U.S., Europe, and the Middle East.
New Techniques and Tools
Nimbus Manticore’s latest campaign is notable for its use of advanced techniques and a new backdoor, codenamed MiniFast (also known as MiniUpdate). This malware is believed to have been developed with the assistance of artificial intelligence, as indicated by an analysis from Check Point Research. The report highlights the group’s evolution in tactics, which now includes previously undocumented methods that enhance their operational capabilities.
Affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC), Nimbus Manticore has historically focused on sectors such as defense, aviation, and telecommunications, employing career-themed phishing lures to deceive targets. These operations have been dubbed the “Iranian Dream Job,” drawing parallels to North Korean tactics used in Operation Dream Job.
Shifts in Attack Strategies
Recent attack chains attributed to Nimbus Manticore reflect a significant shift in their tradecraft. For instance, in February 2026, the group utilized AppDomain hijacking to deliver a variant of malware known as MiniJunk. This was followed by the deployment of the MiniFast backdoor in March and a reliance on SEO poisoning techniques to distribute a trojanized version of Oracle’s SQL Developer software in April.
In the initial campaign prior to the outbreak of conflict, employees in the software and aviation sectors in Saudi Arabia and Australia were targeted with fake job offers. Victims were tricked into downloading a ZIP archive hosted on OnlyOffice, which contained a benign executable that exploited AppDomain hijacking to launch a malicious MiniJunk DLL.
The March 2026 campaign mirrored this approach, with the addition of a trojanized Zoom installer used to deploy the MiniFast backdoor. This suggests a phishing campaign that leveraged fake meeting invitations to lure victims.
AI-Assisted Malware Development
Evidence suggests that Nimbus Manticore employed AI-assisted development techniques in creating MiniFast. This includes features such as extensive error handling, repetitive naming patterns, and detailed error-reporting strings. The malware’s modular code organization, despite its simplicity, indicates a sophisticated level of planning and execution.
Check Point Research also reported the emergence of a fake website masquerading as a download page for SQL Developer. This site, which was promoted through SEO poisoning, aimed to deceive visitors into downloading a weaponized installer that delivered the MiniFast backdoor. This marks a departure from the group’s traditional methods, which typically relied on career-themed phishing lures.
Broader Implications of the Campaign
The implications of these developments extend beyond mere espionage. Sergey Shykevich, threat intelligence group manager at Check Point Research, noted that the group’s ambitions have expanded significantly. They have not only built and deployed a new backdoor during ongoing conflict but have also shifted to a different playbook that includes SEO poisoning.
The campaign’s strategy involved creating a fake SQL Developer download page that was optimized for search engines like Bing and DuckDuckGo, allowing it to attract unsuspecting developers searching for common software. This approach illustrates a marked evolution in the group’s tactics, demonstrating that the conflict has not hindered their operations; rather, it has accelerated them.
Targeting Critical Infrastructure
The recent activities of Iranian hackers have raised alarms regarding potential threats to critical infrastructure. Reports indicate that they have conducted attacks aimed at automatic tank gauge (ATG) systems at gas stations across multiple states in the U.S. While these incidents did not result in physical damage, they have highlighted vulnerabilities that could lead to serious risks, such as undetected gas leaks.
The hackers exploited ATG systems that were inadequately secured, allowing them to manipulate display readings without affecting actual fuel levels. This raises concerns about the broader implications of cyberattacks on essential services.
Conclusion
The recent escalation in cyber operations by Nimbus Manticore underscores the evolving landscape of cybersecurity threats. As the group continues to refine its tactics and tools, organizations across various sectors must remain vigilant. The integration of AI in malware development and the use of sophisticated social engineering techniques highlight the need for enhanced security measures and awareness.
Source: thehackernews.com
Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.


