logo

Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign

ID: 8987df08-eb22-5642-8955-6921927ec5ed

STIX ID: report--8987df08-eb22-5642-8955-6921927ec5ed

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

...
...

**Executive summary:** Check Point Research attributes a multi-wave campaign (Feb–Apr 2026) to IRGC-aligned Nimbus Manticore (UNC1549) targeting aviation, defense and telecoms across the US, Europe and Middle East; the actor shifted from career-themed phishing to search engine poisoning (fake Oracle SQL Developer download pages), used trojanized Zoom installers and OnlyOffice-hosted ZIPs, abused AppDomain hijacking to load malicious .NET DLLs, and deployed a new 64-bit backdoor named MiniFast (JSON-over-HTTP C2 disguised as Chrome) — tooling that shows signs of AI-assisted development.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.