Adversary Intelligence — 2026-05-24
Check Point Tracks Iranian APT Nimbus Manticore Expanding Into Europe With AI-Assisted Malware
BLUFFormal Western indictments or sanctions naming Nimbus Manticore operators remain unlikely through end of 2026, leaving European aviation and software defenders to absorb the cost of the group's AI-enabled tradecraft alone.
Check Point Research reported on May 22 that Nimbus Manticore (UNC1549), an IRGC-affiliated group, ran three campaign waves from February through April 2026 targeting aviation, software, defense, and telecom organizations across the United States, Europe, and the Middle East, activity Check Point tied to the onset of Operation Epic Fury, the U.S. military campaign against Iran launched February 28, 2026 123. The group replaced its MiniJunk toolset with a new backdoor, MiniFast, delivered via AppDomain hijacking; Check Point attributed its modular structure and excessive error handling to AI-assisted development practices, and the group additionally deployed a Trojanized Zoom installer via fake meeting-invitation phishing lures 12. A third wave in April used SEO poisoning, a first for this actor, through a counterfeit SQL Developer download site (getsqldeveloper[.]com) that ranked high on Bing and DuckDuckGo, with campaign files carrying valid SSL.com digital signatures under two certificate names: Gray Matter Software S.R.L. and Kirubel Kerie Negeya 12.
AnalysisFormal indictments or sanctions naming Nimbus Manticore operators are
unlikely by end of 2026. Analytic confidence is low, grounded in the historical pattern of IRGC-affiliated operators escaping formal proceedings despite clear attribution. The diplomatic calculus between Washington and Tehran removes political incentive for escalatory legal action even as attribution sharpens. Reporting rests on a single Check Point investigation amplified by two outlets without independent sourcing. MiniFast's modular architecture and verbose error handling more plausibly reflect deliberate obfuscation tradecraft than confirmed AI integration. Continued SSL.com certificate abuse and SEO poisoning extend dwell time, and European aviation and software firms cannot defer contract screening for IRGC-linked entities against a sanctions designation unlikely to arrive before year-end.
3 sources
- Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
- Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict - Malware News
- Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict - MalwareTips Forums
View in full brief →