Adversary Intelligence — 2026-05-27

IRGC-Linked Nimbus Manticore Deploys MiniFast Backdoor Against US Defense and Aerospace Targets

BLUFAbsent a government advisory by late November 2026, which remains genuinely uncertain, defenders will rely on vendor reporting alone against a group iterating tooling faster than IRGC-attribution cycles typically move.

Check Point Research documented three waves of Nimbus Manticore (UNC1549) activity from February through April 2026, targeting aviation, defense, and software employees across the US, Europe, and the Middle East 123. Both the February and March campaigns used AppDomain hijacking to deliver MiniJunk V2 and a new full-featured backdoor named MiniFast, the March wave also deploying a trojanized Zoom installer distributed via fake meeting invitations 12. In April, the group used SEO poisoning for the first time, registering dozens of domains to push a counterfeit SQL Developer download page to the top of Bing and DuckDuckGo results 23. Palo Alto Networks Unit 42, tracking the group as Screening Serpens, independently identified six new RAT variants across the campaign period, confirmed specific targets in the US, Israel, and UAE, and found C2 traffic routed through Azure-hosted domains unique to each victim, three to five domains per target, to prevent cross-contamination 2.

Analysis
Whether a US agency or Five Eyes partner issues an advisory naming Nimbus Manticore TTPs by late November 2026 is genuinely uncertain. Government advisory cycles for IRGC-attributed actors typically lag vendor disclosure by months, post-ceasefire diplomatic dynamics may reduce urgency to name Tehran formally, and MiniFast's rapid iteration risks rendering current indicators stale before publication. The AI-assisted development markers could equally reflect a shift to junior or contracted developers rather than LLM tooling, leaving the capability-acceleration narrative partially unsupported. Confidence is moderate, grounded in a single vendor primary source with no independent technical collection and no observable signals from government advisory pipelines. A published advisory gives network defenders and critical infrastructure operators a government-sanctioned indicator baseline and triggers formal remediation timelines that commercial vendor reports alone cannot compel.
5 sources
  1. IRGC-linked Nimbus Manticore group attacks defense, aerospace, telecom sectors using Minifast malware toolkit - Industrial Cyber
  2. Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning - The Hacker News
  3. Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign - Infosecurity Magazine
  4. Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
  5. Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns - Palo Alto Networks Unit 42

View in full brief →

UNCLASSIFIED // OPEN SOURCE