Skip to content
Flash Briefing high TransportCommunicationsCritical Infrastructure

Nimbus Manticore Resurfaces with New Backdoor and Expanded European Targeting After Operation Epic Fury

Operation Epic Fury started on 28 February. By March, Nimbus Manticore had a new backdoor, two new delivery techniques, and a significantly expanded European target list. Check Point Research published a detailed breakdown on 22 May. The picture it presents is of a group under operational pressure to collect quickly, adapting faster than their historical tempo would suggest.

The group, briefly

Mandiant tracks Nimbus Manticore as UNC1549, linking it to IRGC intelligence operations. Active since at least 2022, it spent most of its early history targeting aerospace and defence contractors, telecoms operators, and critical infrastructure across Israel, the Gulf states, and Turkey. Western Europe was a secondary concern until late 2025. It shares infrastructure and tradecraft with Smoke Sandstorm.

The signature delivery has always been career-themed phishing: convincing fake job offers from plausible defence industry personas, packaged with documents that sideload malicious DLLs alongside legitimate signed executables. That’s still running. But three things have changed since the conflict started.

Three additions to the toolkit

MiniFast is a previously undocumented backdoor with an interesting characteristic: its code structure and documentation patterns are consistent with LLM-assisted development. The group appears to be iterating faster than prior development cycles would permit. Capabilities cover command execution, file staging, and credential collection. Check Point has observed intrusions involving MiniFast across Denmark, Sweden, and Portugal since February.

SEO poisoning has been added as a delivery channel, a meaningful departure from the group’s prior reliance on direct phishing relationships. Fake download pages impersonating legitimate software are ranking for relevant search terms and dropping MiniFast on users who believe they’re downloading a legitimate tool. The trojanised Oracle SQL Developer installer is the most widely observed lure so far. No prior contact with the target required. Email security controls don’t touch it.

AppDomain Hijacking has replaced DLL sideloading in some campaigns as the execution mechanism. The .NET technique loads malicious code into a legitimate process by manipulating application domain configuration files. It generates less forensic residue than sideloading, and EDR rules tuned specifically for the latter won’t catch it.

Who’s in the crosshairs

Aviation is the most clearly targeted sector. Lures have impersonated recruitment contacts at European carriers, MRO providers, and air traffic control organisations. IRGC priorities, including monitoring Western military logistics and sanctions evasion activity, make aviation operations data and flight scheduling systems plausible collection targets beyond the obvious personnel data.

Western European telecommunications operators face elevated risk. Access to European carrier infrastructure carries dual-use potential: signals intelligence collection and pre-positioning for future disruption. Salt Typhoon demonstrated what carrier access enables. Nimbus Manticore is working the same problem from a different sponsor.

Defence manufacturing and supply chain organisations are in familiar territory from this group, now at scale. Third-party contractors and technology suppliers to defence primes are the known entry point, as they always are.

Detection and response priorities

Add the Check Point indicators to endpoint and network detection. The SEO poisoning vector changes the threat model for user awareness: this isn’t just phishing email anymore; it’s users searching for development tools and landing on convincing malicious download pages. Validate AppDomain Hijacking detection in your EDR coverage. Test whether your tooling flags unexpected app.config or .exe.config modifications in standard application paths. It frequently doesn’t.

Given the trojanised SQL Developer lure, any database tooling installation on endpoints with access to sensitive systems is worth reviewing, even if it looks legitimate.

The pace of retooling here is the strategic signal. IRGC-affiliated groups are historically patient collectors. The current tempo (new backdoor, new delivery, expanded geographic focus in a three-month window) suggests this group is operating under direction to collect fast while the conflict window is open. Patient they are not, right now.