Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms
ID: f0b03bc0-5207-58aa-9ece-ada98d8d87a8
STIX ID: report--f0b03bc0-5207-58aa-9ece-ada98d8d87a8
Feed Name: HackRead
Threat Score
Check Point Research attributes a Feb–Apr 2026 campaign to Iranian APT Nimbus Manticore (UNC1549) that used fake job offers and Zoom installers to deploy MiniJunk and MiniFast backdoors via AppDomain hijacking, hijacked a legitimate Windows scheduled task to maintain persistence, and employed SEO poisoning (fake getsqldevelopercom) to distribute malware; the report highlights AI-assisted, modular development and expanded targeting beyond regional actors to aviation and software firms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
