logo

Fast and Furious – Nimbus Manticore Operations During the Iranian Conflict

ID: 0c77afbe-84d7-528e-b5db-12b53ac8a388

STIX ID: report--0c77afbe-84d7-528e-b5db-12b53ac8a388

Feed Name: Check Point Research

Threat Score
90/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: stcpresearch

...
...

Nimbus Manticore, an IRGC-affiliated APT, resurfaced during Operation Epic Fury (Feb–Apr 2026) using career-themed phishing, a trojanized Zoom installer, and SEO-poisoned fake SQL Developer sites to deploy a new backdoor called MiniFast (evolving from MiniJunk). The report details AppDomain Hijacking and scheduled-task hijacking infection chains, AI-assisted malware development indicators, MiniFast's JSON/C2 protocol and opcode-based tasking, targeted victimology (aviation, software, defense across US, Europe, Middle East), and provides numerous IOCs (SHA256 hashes and malicious domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.