A newly observed cyber campaign linked to the Iranian IRGC-affiliated threat group Nimbus Manticore (also tracked as UNC1549) highlights an evolution in both delivery tactics and malware sophistication.
The activity, uncovered during the ongoing geopolitical conflict tied to Operation Epic Fury launched on February 28, 2026, shows the group adopting SEO poisoning malware for the first time to distribute as legitimate software.
Nimbus Manticore has historically targeted aviation, defense, and telecommunications sectors using career-themed phishing lures. In its latest operations, the group expanded targeting across the United States, Europe, and the Middle East, impersonating aviation firms and software providers to lure victims.
Earlier 2026 campaigns relied on phishing emails delivering ZIP archives hosted on legitimate platforms like OnlyOffice. These archives abused AppDomain hijacking, a technique that forces trusted .NET applications to load malicious DLLs באמצעות crafted .config files, enabling stealthy execution.
Victims executing these files unknowingly triggered multi-stage infection chains that deployed updated versions of the group’s MiniJunk malware.
During Operation Epic Fury, the threat actor introduced a more advanced infection chain using a trojanized Zoom installer. The malware mimicked legitimate installation processes while silently deploying malicious components.
Key techniques observed include:
- Abuse of legitimate signed binaries to evade detection.
- Scheduled task hijacking via Zoom update mechanisms for persistence.
- Multi-stage loaders using obfuscation (ROT13 and reversed strings).
- Strict execution checks to evade sandbox environments.

This campaign marked the debut of a new backdoor named MiniFast, replacing MiniJunk. The malware is a 64-bit DLL that enables full remote control over infected systems, including file exfiltration, command execution, and process manipulation.
MiniFast communicates with command-and-control (C2) servers using structured HTTP requests and JSON-based exchanges, impersonating Chrome browser traffic to blend in with legitimate network activity.
Iranian APT Uses SEO Poisoning
Checkpoint said in a report shared with GBhackers, identified a third campaign phase leveraging SEO poisoning. Attackers created a fake website, getsqldeveloper[.]com, posing as a download portal for Oracle SQL Developer.
To boost visibility, the group registered numerous supporting domains. It used keyword stuffing techniques such as “Download SQL Developer” and “SQL Developer Free.” This manipulation pushed the malicious site to high rankings on search engines like Bing and DuckDuckGo.

Users searching for SQL tools were redirected to the fake site and served a malicious installer that delivered the MiniFast backdoor, marking a shift away from traditional phishing toward search-driven infection vectors.
Analysis of the malware revealed multiple indicators of AI-assisted development. The codebase includes:
- Verbose and repetitive function naming patterns.
- Extensive error handling around simple API calls.
- Modular structure despite relatively simple functionality.
- Embedded debug-style messages and detailed logging.
![The getsqldeveloper[.]com site (Source : Checkpoint).](https://gbhackers.com/wp-content/uploads/2026/05/Screenshot-2026-05-25-102054.png)
These traits suggest the use of large language models or automated coding tools, enabling faster development cycles and rapid adaptation during active operations.
MiniFast operates as a fully featured backdoor with capabilities including:
- Remote command execution via CMD.
- File upload and download.
- Directory and process enumeration.
- Persistence via scheduled tasks.
- Dynamic configuration of communication intervals.
The malware uses Base64-encoded tasking and supports a wide opcode-based command structure, giving operators granular control over compromised systems.
Nimbus Manticore’s latest campaigns demonstrate a significant shift in operational maturity. The adoption of SEO poisoning, AI-assisted malware development, and stealth-focused execution techniques indicates a rapid evolution driven by wartime conditions.
The expansion into U.S. aviation targets and continued focus on high-value sectors align with Iran’s broader intelligence collection objectives. These developments underscore the increasing convergence of cyber operations and geopolitical conflict, with threat actors accelerating innovation to maintain operational effectiveness.
IOCs
| SHA256 |
|---|
| 10fd541674adadfbba99b54280f7e59732746faf2b10ce68521866f737f1e46d |
| eee657ffdb2af8ed6412221e7d5fbf4f5742f2ac2c88f43f12db46af0697de71 |
| 781605ce9d4a9869e846f6c9657d71437cb6240ab27ffbc4cd550c0e06996690 |
| 2c214494fd0bad31473ca8adce78a4f50847876584571e66aadeae70827ec2dc |
| f08b17856616d66492a24dced27f788e235f35f42fa7cd10f315000d3a2f4c03 |
| a57ffb819fe8d98ff925c5d7b239598fe302acf5a13193d7a535040a71298fdf |
| 63d0d3c4a7f71bdbca720903d6a99b832089cc093c64d2938e7e001e56c17ab4 |
| 74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27 |
| bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad |
| ecaf493c320d201d285ef5f61d75744216e47cf1115b4af528f9a78883cc446e |
| 44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250 |
| 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 |
| 485f182f7b74ea4013b2539275a95d21e3a9bf0082c331937af9353a324b36f3 |
| 64530d7e6ee30e4a66d9eeed6b8595c33fd72f5f73409133ca40539e5695df4c |
| 332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17 |
| 9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1 |
| 43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa |
| 8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b |
| 5c3362d20229597d11380f56d1f2eb39647fb6afad7be8392a7abcd18dff12f8 |
| 0291ef318576953f7f3fe287e7775ed1d7c3206119dc7b9cd6d85c02779e6e40 |
| d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2 |
| 38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d |
| f54cd38632ac9da3af3533ae93e92625cbcb04df521dbf1b6acfaa81218f9e8c |
| b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4 |
| 9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84 |
| a13ba3c5aff46e9daf2d23df4b3e3d49dc7236c207c56f0a1433051f3450d441 |
| dfa1e3137a032ee8561a1cd5e1a0f71a10bebb36aef7c336c878638a9c1239ee |
| Domain |
|---|
| business-startup[.]org |
| business-startup.azurewebsites[.]net |
| businessstartup.azurewebsites[.]net |
| buisness-centeral.azurewebsites[.]net |
| buisness-centeral-transportation.azurewebsites[.]net |
| buisness-centeral-transportation[.]com |
| licencemanagers.azurewebsites[.]net |
| licencesupporting.azurewebsites[.]net |
| peerdistsvcmanagers.azurewebsites[.]net |
| nanomatrix.azurewebsites[.]net |
| PremierHealthAdvisory[.]com |
| PremierHealthAdvisory[.]azurewebsites.net |
| Premier-HealthAdvisory[.]azurewebsites.net |
| ramiltonsfinance[.]com |
| ramiltonsfinance.azurewebsites[.]net |
| ramiltons-finance.azurewebsites[.]net |
| globalitconsultants.azurewebsites[.]net |
| globalit-consultants.azurewebsites[.]net |
| global-it-consultants.azurewebsites[.]net |
| global-it-checkers.azurewebsites[.]net |
| global-it-checkbusiness.azurewebsites[.]net |
| global-check-itbusiness.azurewebsites[.]net |
| global-check-business-it.azurewebsites[.]net |
| globalbusiness-checkers-it.azurewebsites[.]net |
| getsqldeveloper[.]com |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





