Nimbus Manticore
Iranian state-sponsored (IRGC) · Espionage / intelligence collection
Tactics, Techniques & Procedures (TTPs)
- Career-themed spear-phishing with fake job offers from defence industry personas
- MiniFast backdoor (LLM-assisted development -- rapid iteration capability)
- AppDomain Hijacking for stealthy .NET code injection (replaces DLL sideloading)
- SEO poisoning for malware delivery -- trojanised software installers (Oracle SQL Developer lure)
- DLL sideloading alongside legitimate signed executables (legacy delivery)
- Credential collection, file staging, and command execution via backdoor
Known Targets
Analyst Notes
Tracked by Mandiant as UNC1549, linked to IRGC intelligence collection operations. Historically focused on aerospace and defence across Israel, the Gulf states, and Turkey. Following the US-Iran conflict that began February 2026 (Operation Epic Fury), the group dramatically accelerated its tempo: new backdoor (MiniFast), two new delivery techniques, and significantly expanded European targeting within a three-month window. The SEO poisoning delivery channel bypasses email security controls entirely -- no prior contact with targets required. The pace of retooling indicates direction to collect rapidly while the conflict window is open.
Also Known As