logo

Detecting Nimbus Manticore and their sideloading infection chains

ID: b416cb0c-bb23-5f26-b8bb-ef07de210c0f

STIX ID: report--b416cb0c-bb23-5f26-b8bb-ef07de210c0f

Feed Name: Nextron Systems

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: Jonathan Peters

...
...

This report documents a targeted hiring-themed phishing campaign attributed to Nimbus Manticore (UNC1549) that uses convincing recruiter personas, lure PDFs (with a distinctive Author metadata string), fake 2FA tooling, and multi-stage .NET payloads delivered via cloud-hosted C2 and trusted-binary sideloading. The article includes a YARA rule to detect the lure PDFs, a comprehensive set of IOCs (file hashes, domains, file paths), and actionable mitigations such as applying AppLocker policies and restricting access to newly-registered domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.