logo

Iranian Hackers Target US Aviation with New Malware and SEO Poisoning

ID: e32cca83-fda6-5bfa-9800-5f11aec86ab9

STIX ID: report--e32cca83-fda6-5bfa-9800-5f11aec86ab9

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

...
...

Iranian state-aligned group Nimbus Manticore (UNC1549) launched a targeted campaign from February–April 2026 against the US aviation sector and related industries using career-themed phishing, SEO poisoning (counterfeit Oracle SQL Developer pages), trojanized Zoom installers and AppDomain hijacking to deploy a new AI-assisted backdoor called MiniFast (64-bit Windows DLL with JSON-based C2 traffic disguised as Chrome). Check Point Research and other vendors observed multiple waves, multi-region targeting, and recommend blocking malicious domains, monitoring for suspicious .NET DLL loads/AppDomain hijacking, and detecting MiniFast’s JSON-over-HTTP C2 patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.