Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Iranian APT Targets Aviation, Software Companies With Updated Tools

0
Medium
Vulnerability
Published: 05/26/2026 (05/26/2026, 13:26:17 UTC)
Source: SecurityWeek

Description

Nimbus Manticore has continued its operations during and after the US military campaign against Iran. The post Iranian APT Targets Aviation, Software Companies With Updated Tools appeared first on SecurityWeek .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/26/2026, 13:32:23 UTC

Technical Analysis

Nimbus Manticore (also known as Bohrium, Smoke Sandstorm, TA455, UNC1549), a subgroup of Charming Kitten (APT35) linked to Iran's IRGC, has updated its toolset and tactics in ongoing cyber espionage campaigns targeting aviation and software sectors. The group employs phishing with job offer lures and trojanized installers (e.g., Zoom installer) to deliver backdoors like MiniJunk and MiniFast. MiniFast is a 64-bit Windows PE DLL that impersonates Chrome and supports extensive remote operations including file and process manipulation, scheduled task creation, and additional payload deployment. The group uses AppDomain hijacking via malicious XML .config files to load DLLs in .NET applications. Campaigns have targeted organizations in Saudi Arabia, Australia, Europe, the Middle East, and recently the US. Nimbus Manticore also uses SEO poisoning to promote fake download sites. The group’s rapid tool development is likely aided by AI and LLM-based techniques. No specific vulnerabilities or patches are identified in the source content.

Potential Impact

The threat enables persistent remote access and control over targeted systems in aviation and software companies, allowing attackers to manipulate files and processes, exfiltrate data, and deploy further malware. The targeting of critical sectors such as aerospace and defense, including US organizations, poses risks to sensitive information and operational security. However, there is no indication of widespread exploitation or known active exploits beyond targeted intrusions. The campaigns leverage social engineering and supply chain deception rather than exploiting software vulnerabilities directly.

Mitigation Recommendations

No vendor advisories or patches are referenced for this threat. Organizations should focus on detecting and blocking phishing campaigns, especially those involving job offer lures and trojanized installers. Monitoring for AppDomain hijacking techniques and suspicious DLL loading in .NET applications is recommended. Employing endpoint detection and response solutions capable of identifying backdoors like MiniJunk and MiniFast can aid in mitigation. Since this is an ongoing APT campaign, organizations should maintain updated threat intelligence and apply security best practices relevant to phishing and malware defense. Patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/iranian-apt-targets-aviation-software-companies-with-updated-tools/","fetched":true,"fetchedAt":"2026-05-26T13:32:12.770Z","wordCount":1236}

Threat ID: 6a15a0dc891d628fdc364a3f

Added to database: 05/26/2026, 13:32:12 UTC

Last enriched: 05/26/2026, 13:32:23 UTC

Last updated: 07/30/2026, 09:33:53 UTC

Views: 119

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses