Friday, September 11, 2026

Iranian APT Uses SEO Poisoning to Spread Fake SQL Developer Malware

A newly observed cyber campaign linked to the Iranian IRGC-affiliated threat group Nimbus Manticore (also tracked as UNC1549) highlights an evolution in both delivery tactics and malware sophistication.

The activity, uncovered during the ongoing geopolitical conflict tied to Operation Epic Fury launched on February 28, 2026, shows the group adopting SEO poisoning malware for the first time to distribute as legitimate software.

Nimbus Manticore has historically targeted aviation, defense, and telecommunications sectors using career-themed phishing lures. In its latest operations, the group expanded targeting across the United States, Europe, and the Middle East, impersonating aviation firms and software providers to lure victims.

Earlier 2026 campaigns relied on phishing emails delivering ZIP archives hosted on legitimate platforms like OnlyOffice. These archives abused AppDomain hijacking, a technique that forces trusted .NET applications to load malicious DLLs באמצעות crafted .config files, enabling stealthy execution.

Victims executing these files unknowingly triggered multi-stage infection chains that deployed updated versions of the group’s MiniJunk malware.

During Operation Epic Fury, the threat actor introduced a more advanced infection chain using a trojanized Zoom installer. The malware mimicked legitimate installation processes while silently deploying malicious components.

Key techniques observed include:

  • Abuse of legitimate signed binaries to evade detection.
  • Scheduled task hijacking via Zoom update mechanisms for persistence.
  • Multi-stage loaders using obfuscation (ROT13 and reversed strings).
  • Strict execution checks to evade sandbox environments.
2026 campaign timeline during the ongoing military campaign (Source : Checkpoint).
2026 campaign timeline during the ongoing military campaign (Source : Checkpoint).

This campaign marked the debut of a new backdoor named MiniFast, replacing MiniJunk. The malware is a 64-bit DLL that enables full remote control over infected systems, including file exfiltration, command execution, and process manipulation.

MiniFast communicates with command-and-control (C2) servers using structured HTTP requests and JSON-based exchanges, impersonating Chrome browser traffic to blend in with legitimate network activity.

Iranian APT Uses SEO Poisoning

Checkpoint said in a report shared with GBhackers, identified a third campaign phase leveraging SEO poisoning. Attackers created a fake website, getsqldeveloper[.]com, posing as a download portal for Oracle SQL Developer.

To boost visibility, the group registered numerous supporting domains. It used keyword stuffing techniques such as “Download SQL Developer” and “SQL Developer Free.” This manipulation pushed the malicious site to high rankings on search engines like Bing and DuckDuckGo.


Campaign 2: During Operation Epic Fury – Attack Chain (Source : Checkpoint).
Campaign 2: During Operation Epic Fury – Attack Chain (Source : Checkpoint).

Users searching for SQL tools were redirected to the fake site and served a malicious installer that delivered the MiniFast backdoor, marking a shift away from traditional phishing toward search-driven infection vectors.

Analysis of the malware revealed multiple indicators of AI-assisted development. The codebase includes:

  • Verbose and repetitive function naming patterns.
  • Extensive error handling around simple API calls.
  • Modular structure despite relatively simple functionality.
  • Embedded debug-style messages and detailed logging.
The getsqldeveloper[.]com site (Source : Checkpoint).
The getsqldeveloper[.]com site (Source : Checkpoint).

These traits suggest the use of large language models or automated coding tools, enabling faster development cycles and rapid adaptation during active operations.

MiniFast operates as a fully featured backdoor with capabilities including:

  • Remote command execution via CMD.
  • File upload and download.
  • Directory and process enumeration.
  • Persistence via scheduled tasks.
  • Dynamic configuration of communication intervals.

The malware uses Base64-encoded tasking and supports a wide opcode-based command structure, giving operators granular control over compromised systems.

Nimbus Manticore’s latest campaigns demonstrate a significant shift in operational maturity. The adoption of SEO poisoning, AI-assisted malware development, and stealth-focused execution techniques indicates a rapid evolution driven by wartime conditions.

The expansion into U.S. aviation targets and continued focus on high-value sectors align with Iran’s broader intelligence collection objectives. These developments underscore the increasing convergence of cyber operations and geopolitical conflict, with threat actors accelerating innovation to maintain operational effectiveness.

IOCs

SHA256
10fd541674adadfbba99b54280f7e59732746faf2b10ce68521866f737f1e46d
eee657ffdb2af8ed6412221e7d5fbf4f5742f2ac2c88f43f12db46af0697de71
781605ce9d4a9869e846f6c9657d71437cb6240ab27ffbc4cd550c0e06996690
2c214494fd0bad31473ca8adce78a4f50847876584571e66aadeae70827ec2dc
f08b17856616d66492a24dced27f788e235f35f42fa7cd10f315000d3a2f4c03
a57ffb819fe8d98ff925c5d7b239598fe302acf5a13193d7a535040a71298fdf
63d0d3c4a7f71bdbca720903d6a99b832089cc093c64d2938e7e001e56c17ab4
74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27
bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad
ecaf493c320d201d285ef5f61d75744216e47cf1115b4af528f9a78883cc446e
44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250
0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864
485f182f7b74ea4013b2539275a95d21e3a9bf0082c331937af9353a324b36f3
64530d7e6ee30e4a66d9eeed6b8595c33fd72f5f73409133ca40539e5695df4c
332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17
9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1
43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa
8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b
5c3362d20229597d11380f56d1f2eb39647fb6afad7be8392a7abcd18dff12f8
0291ef318576953f7f3fe287e7775ed1d7c3206119dc7b9cd6d85c02779e6e40
d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2
38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d
f54cd38632ac9da3af3533ae93e92625cbcb04df521dbf1b6acfaa81218f9e8c
b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4
9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84
a13ba3c5aff46e9daf2d23df4b3e3d49dc7236c207c56f0a1433051f3450d441
dfa1e3137a032ee8561a1cd5e1a0f71a10bebb36aef7c336c878638a9c1239ee
Domain
business-startup[.]org
business-startup.azurewebsites[.]net
businessstartup.azurewebsites[.]net
buisness-centeral.azurewebsites[.]net
buisness-centeral-transportation.azurewebsites[.]net
buisness-centeral-transportation[.]com
licencemanagers.azurewebsites[.]net
licencesupporting.azurewebsites[.]net
peerdistsvcmanagers.azurewebsites[.]net
nanomatrix.azurewebsites[.]net
PremierHealthAdvisory[.]com
PremierHealthAdvisory[.]azurewebsites.net
Premier-HealthAdvisory[.]azurewebsites.net
ramiltonsfinance[.]com
ramiltonsfinance.azurewebsites[.]net
ramiltons-finance.azurewebsites[.]net
globalitconsultants.azurewebsites[.]net
globalit-consultants.azurewebsites[.]net
global-it-consultants.azurewebsites[.]net
global-it-checkers.azurewebsites[.]net
global-it-checkbusiness.azurewebsites[.]net
global-check-itbusiness.azurewebsites[.]net
global-check-business-it.azurewebsites[.]net
globalbusiness-checkers-it.azurewebsites[.]net
getsqldeveloper[.]com

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News