Iranian Hackers Accelerate MiniFast and MiniJunk V2 Deployment through Phishing and SEO Poisoning

Published:

spot_img

Iranian Hackers Accelerate MiniFast and MiniJunk V2 Deployment through Phishing and SEO Poisoning

Recent developments in cyber warfare have seen the Iranian state-sponsored group known as Nimbus Manticore, also referred to as Screening Serpens and UNC1549, intensifying its operations. Following a joint U.S.-Israeli military campaign against Iran in late February 2026, the group has launched a series of sophisticated attacks targeting organizations in the aviation and software sectors across the U.S., Europe, and the Middle East.

New Techniques and Tools

Nimbus Manticore’s latest campaign is notable for its use of advanced techniques and a new backdoor, codenamed MiniFast (also known as MiniUpdate). This malware is believed to have been developed with the assistance of artificial intelligence, as indicated by an analysis from Check Point Research. The report highlights the group’s evolution in tactics, which now includes previously undocumented methods that enhance their operational capabilities.

Affiliated with Iran’s Islamic Revolutionary Guard Corps (IRGC), Nimbus Manticore has historically focused on sectors such as defense, aviation, and telecommunications, employing career-themed phishing lures to deceive targets. These operations have been dubbed the “Iranian Dream Job,” drawing parallels to North Korean tactics used in Operation Dream Job.

Shifts in Attack Strategies

Recent attack chains attributed to Nimbus Manticore reflect a significant shift in their tradecraft. For instance, in February 2026, the group utilized AppDomain hijacking to deliver a variant of malware known as MiniJunk. This was followed by the deployment of the MiniFast backdoor in March and a reliance on SEO poisoning techniques to distribute a trojanized version of Oracle’s SQL Developer software in April.

In the initial campaign prior to the outbreak of conflict, employees in the software and aviation sectors in Saudi Arabia and Australia were targeted with fake job offers. Victims were tricked into downloading a ZIP archive hosted on OnlyOffice, which contained a benign executable that exploited AppDomain hijacking to launch a malicious MiniJunk DLL.

The March 2026 campaign mirrored this approach, with the addition of a trojanized Zoom installer used to deploy the MiniFast backdoor. This suggests a phishing campaign that leveraged fake meeting invitations to lure victims.

AI-Assisted Malware Development

Evidence suggests that Nimbus Manticore employed AI-assisted development techniques in creating MiniFast. This includes features such as extensive error handling, repetitive naming patterns, and detailed error-reporting strings. The malware’s modular code organization, despite its simplicity, indicates a sophisticated level of planning and execution.

Check Point Research also reported the emergence of a fake website masquerading as a download page for SQL Developer. This site, which was promoted through SEO poisoning, aimed to deceive visitors into downloading a weaponized installer that delivered the MiniFast backdoor. This marks a departure from the group’s traditional methods, which typically relied on career-themed phishing lures.

Broader Implications of the Campaign

The implications of these developments extend beyond mere espionage. Sergey Shykevich, threat intelligence group manager at Check Point Research, noted that the group’s ambitions have expanded significantly. They have not only built and deployed a new backdoor during ongoing conflict but have also shifted to a different playbook that includes SEO poisoning.

The campaign’s strategy involved creating a fake SQL Developer download page that was optimized for search engines like Bing and DuckDuckGo, allowing it to attract unsuspecting developers searching for common software. This approach illustrates a marked evolution in the group’s tactics, demonstrating that the conflict has not hindered their operations; rather, it has accelerated them.

Targeting Critical Infrastructure

The recent activities of Iranian hackers have raised alarms regarding potential threats to critical infrastructure. Reports indicate that they have conducted attacks aimed at automatic tank gauge (ATG) systems at gas stations across multiple states in the U.S. While these incidents did not result in physical damage, they have highlighted vulnerabilities that could lead to serious risks, such as undetected gas leaks.

The hackers exploited ATG systems that were inadequately secured, allowing them to manipulate display readings without affecting actual fuel levels. This raises concerns about the broader implications of cyberattacks on essential services.

Conclusion

The recent escalation in cyber operations by Nimbus Manticore underscores the evolving landscape of cybersecurity threats. As the group continues to refine its tactics and tools, organizations across various sectors must remain vigilant. The integration of AI in malware development and the use of sophisticated social engineering techniques highlight the need for enhanced security measures and awareness.

Source: thehackernews.com

Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.

spot_img

Related articles

Recent articles

Dutch Police Investigate Vishing Call as Key Lead in Odido Cyberattack Exposing 6.39 Million Customers

Dutch Police Investigate Vishing Call as Key Lead in Odido Cyberattack Exposing 6.39 Million Customers The recent cyberattack on Odido, a major Dutch telecom provider,...

Cybersecurity Researchers Uncover “Ghostcommit”: A New Image-Based Attack Manipulating AI to Steal Sensitive Data

Cybersecurity Researchers Uncover "Ghostcommit": A New Image-Based Attack Manipulating AI to Steal Sensitive Data Cybersecurity researchers have identified a sophisticated supply chain attack technique dubbed...

Irvinder Singh Lail Appointed to Strengthen J.S. Held’s Global Capability Leadership

Irvinder Singh Lail Appointed to Strengthen J.S. Held's Global Capability Leadership In a significant move for the global consulting landscape, J.S. Held has appointed Irvinder...

From 17,000 to 1.1 Million Assets: Lumen Technologies Strengthens Exposure Management Through Comprehensive Data Reconciliation

From 17,000 to 1.1 Million Assets: Lumen Technologies Strengthens Exposure Management Through Comprehensive Data Reconciliation In a landscape where cybersecurity threats are increasingly sophisticated, accurate...