logo

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

ID: bc362ca8-b40c-595b-9821-7d3e051c80f9

STIX ID: report--bc362ca8-b40c-595b-9821-7d3e051c80f9

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: [email protected] (The Hacker News)

...
...

Nimbus Manticore (aka Screening Serpens / UNC1549), an Iranian state-linked APT, ran coordinated campaigns from February–April 2026 targeting aviation, software, defense, telecom and energy organizations across multiple countries. The actor deployed new backdoors (MiniFast/MiniUpdate and MiniJunk V2), likely using AI-assisted development, and employed AppDomain hijacking, trojanized installers, phishing (including fake job offers and spoofed meeting invites), SEO poisoning, and persistence mechanisms to enable long-term remote command execution and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.