Threats Feed
- Public
Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning
During the 2026 Operation Epic Fury, the IRGC-affiliated threat actor Nimbus Manticore (UNC1549) launched sophisticated cyber campaigns targeting the aviation, software, defense, and telecommunication sectors across the United States, Europe, Australia, and the Middle East (specifically Israel, Saudi Arabia, and the UAE). The group demonstrated rapid capability evolution by deploying a new AI-assisted backdoor named MiniFast. Attackers leveraged AppDomain Hijacking, trojanized Zoom installers, and SEO poisoning to deliver malware via fake SQL Developer download sites and career-themed phishing lures. These operations highlight Nimbus Manticore's high adaptability and continuous development of advanced stealth and persistence mechanisms amid the Iranian conflict.
read more about Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning - Public
Nimbus Manticore Expands Cyber-Espionage Campaigns Across Europe
Nimbus Manticore, an Iranian threat actor overlapping with UNC1549 and Smoke Sandstorm, has intensified its espionage operations against defense manufacturing, telecommunications, and aviation sectors in Western Europe, notably Denmark, Sweden, and Portugal. The group uses spear-phishing lures posing as HR recruiters to deliver multi-stage DLL side-loading malware via fake career portals. Its evolving toolset—MiniJunk backdoor and MiniBrowse stealer—employs advanced obfuscation, code signing, and cloud-based C2 infrastructure on Azure and Cloudflare to evade detection. The campaign reflects a highly sophisticated, well-resourced actor aligned with IRGC intelligence objectives.
read more about Nimbus Manticore Expands Cyber-Espionage Campaigns Across Europe - Public
Nimbus Manticore Expands Cyber-Espionage Campaigns Across Europe
Nimbus Manticore, an Iranian threat actor overlapping with UNC1549 and Smoke Sandstorm, has intensified its espionage operations against defense manufacturing, telecommunications, and aviation sectors in Western Europe, notably Denmark, Sweden, and Portugal. The group uses spear-phishing lures posing as HR recruiters to deliver multi-stage DLL side-loading malware via fake career portals. Its evolving toolset—MiniJunk backdoor and MiniBrowse stealer—employs advanced obfuscation, code signing, and cloud-based C2 infrastructure on Azure and Cloudflare to evade detection. The campaign reflects a highly sophisticated, well-resourced actor aligned with IRGC intelligence objectives.
read more about Nimbus Manticore Expands Cyber-Espionage Campaigns Across Europe - Public
Nimbus Manticore Expands Cyber-Espionage Campaigns Across Europe
Nimbus Manticore, an Iranian threat actor overlapping with UNC1549 and Smoke Sandstorm, has intensified its espionage operations against defense manufacturing, telecommunications, and aviation sectors in Western Europe, notably Denmark, Sweden, and Portugal. The group uses spear-phishing lures posing as HR recruiters to deliver multi-stage DLL side-loading malware via fake career portals. Its evolving toolset—MiniJunk backdoor and MiniBrowse stealer—employs advanced obfuscation, code signing, and cloud-based C2 infrastructure on Azure and Cloudflare to evade detection. The campaign reflects a highly sophisticated, well-resourced actor aligned with IRGC intelligence objectives.
read more about Nimbus Manticore Expands Cyber-Espionage Campaigns Across Europe