Threats Feed|Nimbus Manticore|Last Updated 10/06/2026|AuthorCertfa Radar|Publish Date22/05/2026

Nimbus Manticore's Operation Epic Fury: AI-Assisted Malware and SEO Poisoning

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Backdoor,Dropper,Trojan,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

During the 2026 Operation Epic Fury, the IRGC-affiliated threat actor Nimbus Manticore (UNC1549) launched sophisticated cyber campaigns targeting the aviation, software, defense, and telecommunication sectors across the United States, Europe, Australia, and the Middle East (specifically Israel, Saudi Arabia, and the UAE). The group demonstrated rapid capability evolution by deploying a new AI-assisted backdoor named MiniFast. Attackers leveraged AppDomain Hijacking, trojanized Zoom installers, and SEO poisoning to deliver malware via fake SQL Developer download sites and career-themed phishing lures. These operations highlight Nimbus Manticore's high adaptability and continuous development of advanced stealth and persistence mechanisms amid the Iranian conflict.

Detected Targets

TypeDescriptionConfidence
SectorInformation Technology
Verified
SectorAerospace
Verified
RegionAustralia
Verified
RegionIsrael
Verified
RegionSaudi Arabia
Verified
RegionUnited States
Verified
RegionMiddle East Countries
Verified
RegionEuropean Countries
Verified

Extracted IOCs

  • buisness-centeral-transportation[.]com
  • business-startup[.]org
  • getsqldeveloper[.]com
  • premierhealthadvisory[.]com
  • ramiltonsfinance[.]com
  • buisness-centeral.azurewebsites[.]net
  • buisness-centeral-transportation.azurewebsites[.]net
  • business-startup.azurewebsites[.]net
  • businessstartup.azurewebsites[.]net
  • globalbusiness-checkers-it.azurewebsites[.]net
  • global-check-business-it.azurewebsites[.]net
  • global-check-itbusiness.azurewebsites[.]net
  • global-it-checkbusiness.azurewebsites[.]net
  • global-it-checkers.azurewebsites[.]net
  • global-it-consultants.azurewebsites[.]net
  • globalit-consultants.azurewebsites[.]net
  • globalitconsultants.azurewebsites[.]net
  • licencemanagers.azurewebsites[.]net
  • licencesupporting.azurewebsites[.]net
  • nanomatrix.azurewebsites[.]net
  • peerdistsvcmanagers.azurewebsites[.]net
  • premier-healthadvisory.azurewebsites[.]net
  • premierhealthadvisory.azurewebsites[.]net
  • ramiltons-finance.azurewebsites[.]net
  • ramiltonsfinance.azurewebsites[.]net
  • 0291ef318576953f7f3fe287e7775ed1d7c3206119dc7b9cd6d85c02779e6e40
  • 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864
  • 10fd541674adadfbba99b54280f7e59732746faf2b10ce68521866f737f1e46d
  • 2c214494fd0bad31473ca8adce78a4f50847876584571e66aadeae70827ec2dc
  • 332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17
  • 38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d
  • 43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa
  • 44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250
  • 485f182f7b74ea4013b2539275a95d21e3a9bf0082c331937af9353a324b36f3
  • 5c3362d20229597d11380f56d1f2eb39647fb6afad7be8392a7abcd18dff12f8
  • 63d0d3c4a7f71bdbca720903d6a99b832089cc093c64d2938e7e001e56c17ab4
  • 64530d7e6ee30e4a66d9eeed6b8595c33fd72f5f73409133ca40539e5695df4c
  • 74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27
  • 781605ce9d4a9869e846f6c9657d71437cb6240ab27ffbc4cd550c0e06996690
  • 8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b
  • 9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84
  • 9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1
  • a13ba3c5aff46e9daf2d23df4b3e3d49dc7236c207c56f0a1433051f3450d441
  • a57ffb819fe8d98ff925c5d7b239598fe302acf5a13193d7a535040a71298fdf
  • b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4
  • bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad
  • d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2
  • dfa1e3137a032ee8561a1cd5e1a0f71a10bebb36aef7c336c878638a9c1239ee
  • ecaf493c320d201d285ef5f61d75744216e47cf1115b4af528f9a78883cc446e
  • eee657ffdb2af8ed6412221e7d5fbf4f5742f2ac2c88f43f12db46af0697de71
  • f08b17856616d66492a24dced27f788e235f35f42fa7cd10f315000d3a2f4c03
  • f54cd38632ac9da3af3533ae93e92625cbcb04df521dbf1b6acfaa81218f9e8c
download

Tip: 52 related IOCs (0 IP, 25 domain, 0 URL, 0 email, 27 file hash) to this threat have been found.

FAQs

Understanding the Nimbus Manticore Cyber Campaign

During recent geopolitical conflicts in early 2026, a sophisticated cyber espionage campaign was launched against multiple international targets. The attackers used fake software downloads and fraudulent job offers to trick users into installing malicious programs. This allowed the attackers to secretly access, monitor, and control infected computers.

The attack was carried out by Nimbus Manticore, a highly capable threat group affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC). This group is well-known for its complex cyber tools and has a long history of targeting the defense, aviation, and telecommunications sectors.

The primary nature of the attack was cyber espionage designed to support broader Iranian strategic and intelligence-gathering efforts during a military conflict. The attackers aimed to establish long-term, hidden access on victim networks to steal data, execute remote commands, and maintain operational availability.

The targeting was global but focused heavily on the United States, Europe, and the Middle East, including countries like Israel, Saudi Arabia, and the United Arab Emirates. There was also documented targeting of organizations in Australia.

Yes, the campaign specifically focused on employees and organizations within the aviation and software development sectors. The attackers deliberately tailored their fake job offers and software lures to appeal to professionals working in these specific fields.

The attackers tricked victims into downloading malicious files disguised as job opportunities or legitimate software like Zoom and SQL Developer. Once downloaded, the malware used artificial intelligence-assisted code and clever tricks to blend in with normal computer processes, hiding its presence while securely reporting back to the attackers.

Aviation and software development sectors are highly attractive because they align with the IRGC’s broader intelligence collection priorities. Gaining access to these networks can provide strategic advantages, valuable intellectual property, and insights into defense, logistics, and software supply chains.

Organizations should increase their monitoring for suspicious network traffic and unexpected changes to automated system tasks. Individuals should remain highly cautious of unsolicited job offers containing file attachments and ensure they only download software directly from official, verified vendor websites rather than relying on search engine results.

This is a highly targeted issue focused on specific professionals and industries rather than a widespread attack on the general public. The attackers carefully designed their lures, such as impersonating US domestic airlines, to ensnare specific individuals of strategic interest to their intelligence goals.

About Affiliation
Nimbus Manticore
Nimbus Manticore is Check Point Research's designation for a mature Iran-nexus APT group also tracked as UNC1549 (Mandiant) and Smoke Sandstorm (Microsoft), with assessed links to the IRGC. Active since at least 2022, the group conducts targeted spear phishing campaigns that impersonate HR recruiters from companies such as Boeing, Airbus, and Rheinmetall, directing victims to fake career portals that deliver the Minibike/SlugResin backdoor family. In 2025, the group significantly expanded operations into Western Europe — targeting Denmark, Sweden, and Portugal — alongside its traditional Middle East focus on Israel and the UAE, in sectors including defense, aerospace, telecommunications, and satellite providers. The group's toolset evolved to include MiniJunk, a heavily obfuscated Minibike derivative using DLL sideloading via undocumented NT APIs, and MiniBrowse, a credential stealer targeting Chrome and Edge. Command and control infrastructure is hosted on Azure App Service behind Cloudflare, providing resilience and traffic blending. A related cluster, Subtle Snail, shares code similarities but is tracked separately.
View Nimbus Manticore's Insights