Adversary Intelligence — 2026-05-22

Unit 42 Exposes Iranian APT Screening Serpens Targeting US and Allied Aerospace and Defense Sectors With New Malware

BLUFScreening Serpens' AppDomainManager hijacking blinds standard EDR to .NET execution, leaving US and allied aerospace and defense networks exposed unless defenders augment detection beyond ETW-dependent telemetry.

Palo Alto Networks Unit 42 on May 22 identified six new RAT variants in two families, MiniUpdate and MiniJunk V2, deployed by Iranian APT Screening Serpens against targets in the U.S., Israel, UAE, and at least two additional Middle Eastern entities between February and April 2026 12. Both families used tailored spear-phishing lures, with the U.S. campaign impersonating a global air carrier's job portal and the Israeli campaign spoofing a video conferencing installer 1. Unit 42 reported that MiniUpdate variants employed AppDomainManager hijacking to disable Event Tracing for Windows and bypass assembly signature validation, stripping the telemetry endpoint detection tools rely on to monitor .NET execution 1. Cybersecurity Dive noted that the February MiniJunk V2 campaign against a Middle Eastern IT professional involved reconnaissance from late 2025, with attackers exploiting the target's job-search activity to craft the lure 2.

Analysis
AppDomainManager hijacking operates at the CLR configuration layer, stripping the ETW telemetry that endpoint tools require to flag malicious assembly loading. Aerospace and defense organizations across U.S. and partner networks must treat standard .NET monitoring as insufficient against this actor. Six malware variants across two families emerged in roughly ten weeks, with per-target C2 rotated across Azure-hosted domains and late-2025 reconnaissance confirming multi-month target preparation predating the regional conflict. Drawn entirely from Unit 42's primary technical report, with Cybersecurity Dive adding no independent collection, the affected-nation framing rests on VirusTotal metadata that cannot exclude researcher sandboxing or honeypot uploads.
2 sources
  1. Tracking Iranian APT Screening Serpens 2026 Espionage Campaigns - Palo Alto Unit 42
  2. Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages - Cybersecurity Dive

View in full brief →

UNCLASSIFIED // OPEN SOURCE