The images in this article were generated with artificial intelligence. How we publish
The campaign attributed to the Iranian actor known as Nimbus Manticore(also Screening Serpens or UNS1549) represents a worrying evolution in cyberespionage techniques: not only is there a leap in the variety of baits - false job offers, invitations to meetings and manipulated download pages - but also in the sophistication of the malware used, including the new backdoor baptized as MiniFast / MiniUpdate.
According to public analysis and industry reports, the activity observed between February and April 2026 combines traditional speed techniques with less expected tactics such as SEO poisoning to position false download pages (e.g., an Oracle SQL Developer) and the abuse of AppDomain hijacking to load malicious DLs. This diversification increases the entry routes and makes detection based only on static indicators or mail filters difficult.

A relevant and novel aspect is the evidence of development assisted by artificial intelligence in the creation of MiniFast: repetitive patterns in function names, detailed cleansing messages, excessive error management and a modular code organization. These features suggest that attackers are using tools that accelerate malware generation and reduce the learning curve, which in turn allows the deployment of new RAT families (Remote Access Trojan) in short periods during geopolitical conflicts.
The technical capabilities of the backdoor are unique to a tool designed for persistent operations: HTTP communication for tasks and exfiltration, remote execution of commands, process handling, DLs loading, creation of tasks programmed for persistence and jitter-sounding parameters to evade easy-to-detect network patterns. This flexibility makes MiniFast a long-range platform for espionage and subsequent movements within compromised networks.
The observed operational pattern - highly personalized job offers, invitations to false meetings and now malicious SEO - shows a clear intention to seek both specific human objectives and opportunistic victims (developers looking for legitimate software). The use of page positions in search engines means that even organizations with basic controls can be reached if employees download software from apparently higher sources in search results.
The implications for the private sector and critical infrastructure are clear: Iranian state actors have demonstrated the ability to attack targets outside their region, including energy companies and critical suppliers, and have shown interest in industrial and control systems that, although in some cases only allowed for the handling of readings, pose greater potential risks if exploited with destructive intentions.
In order to mitigate the immediate risk, there is a need to strengthen controls on several fronts. At the organizational level, the verification of software download origins - confirming digital signatures and always downloading from official repositories - and strengthening the management of domains and reputation in search engines should be prioritized. Security teams should fine-tune detection rules for HTTP beaconing behaviors, unusual use of cmd.exe, creation of programmed tasks and dynamic DLL loads, relying on EDR solutions and the intelligence intake of threats such as that published by specialized groups.
Awareness-raising and training remain critical: employees must be trained to detect false recruitment messaging and virtual meeting supplanting tactics, while administrators must review and close out unnecessary exposed services (e.g. ATG systems or control panels without authentication). In addition, network segmentation and the limitation of privileges reduce the impact of an initial intrusion and facilitate containment.
In terms of detection and response, it is essential to integrate telemetry signals with context: correlate access to newly registered or SEO-positioned domains with executable downloads and post-exploitation activities; enrich analysis with community-shared IOC and TTP; and test RATs response playbooks that include evidence preservation, domain blocking and restoration from clean copies. Organizations that manage critical infrastructure should coordinate with national authorities and share information with peer industrialists.

The phenomenon also raises a strategic issue: the availability of IA tools to accelerate malware development reduces the technical barrier for resource actors, forcing defenders and regulators to update security frameworks, behaviour-based detection investments and international cooperation for attribution and mitigation. To keep up, the security community needs to publish technical research, share indicators and work with search and hosting providers to stop SEO abuse.
Those who want to deepen technical observations and shared intelligence can consult the industry's general analyses and publications, for example in the research repositories of the Check Point Research and Unit 42 of Palo Alto Networks, which have documented patterns and artifacts associated with these campaigns: Check Point Research and Unit 42. To understand techniques and tactics of adversaries at the tactical level, the MITRE ATT & CK base provides a useful reference framework: MITRE ATT & CK.
In short, the activity attributed to Nimbus Manticore is a reminder that cyberspace adapts and accelerates in times of geopolitical tension: the combination of refined social engineering, legitimate channel abuse and the possible use of IA in malware production requires a proactive defensive posture, based on source verification, behavioral detection and collaboration between industry and authorities.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...