Skip to content
← All Threat Actors
Nation-State high Iran

Screening Serpens

Iranian state-sponsored (IRGC-linked) · Espionage / intelligence collection / regional conflict intelligence

Reports 1
Active Since 2022
Last Reported 4 Jun 2026
Sectors Targeted communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Personalised spear-phishing themed around aerospace and defence job listings ("Iranian Dream Job" approach)
  • MiniUpdate and MiniJunk V2 RAT families — six new variants documented in 2026
  • AppDomainManager hijacking for EDR bypass: malicious .NET assembly loaded during application startup before endpoint tooling hooks
  • Azure-hosted C2 infrastructure — dedicated domain clusters per intrusion set to prevent cross-contamination
  • DLL sideloading alongside legitimate signed executables for payload delivery
  • Operational tempo surge timed to regional conflict escalation (from February 2026)

Known Targets

Aerospace sector professionals (US, Israel, UAE)Defence manufacturing organisationsTelecommunications operatorsMiddle Eastern government entitiesIsraeli and Gulf state targets

Analyst Notes

Iran-nexus APT tracked by Palo Alto Networks Unit 42 as Screening Serpens and by Mandiant as UNC1549; shares infrastructure and tradecraft with Smoke Sandstorm. Unit 42 documented six new RAT variants (MiniUpdate, MiniJunk V2 families) deployed in a campaign wave between February and April 2026 — directly correlated with the escalation of regional conflict from 28 February 2026. The AppDomainManager hijacking technique is specifically engineered to execute before EDR products initialise their hooks, making it effective against organisations with modern endpoint security tooling. Spear-phishing lures impersonating a major commercial airline and defence sector employers demonstrate investment in personalised social engineering at scale. See also: UNC1549 (Screening Serpens / Nimbus Manticore) profile.

Also Known As

UNC1549Smoke SandstormNimbus Manticore