MINIBIKE is a custom modular C++ backdoor associated with the Iran-linked espionage cluster UNC1549, also tracked as Nimbus Manticore and linked in public reporting to Tortoiseshell and Smoke Sandstorm. It has been used since at least 2022 in long-running espionage operations targeting aerospace, aviation, defense, telecommunications, satellite communications, research, and related supply-chain organizations, particularly in the Middle East and later in Europe and other regions.
MINIBIKE is designed for covert post-compromise access, reconnaissance, credential and data theft, and follow-on payload delivery. Reported capabilities include system information collection, directory enumeration, command execution, file upload and exfiltration, deployment of additional payloads, keylogging, screenshot capture, and theft of credentials and browser or Outlook data. Multiple reports also describe its use for persistence and long-dwell access, with operators rotating variants and infrastructure while preserving core functionality. Later variants added chunked file exfiltration and continued to emphasize stealth and signature evasion.
The malware has commonly been delivered through highly targeted Dream Job-style social engineering, including spearphishing and fake recruitment portals impersonating aerospace, defense, aviation, and telecommunications employers. Execution chains have relied heavily on DLL sideloading and, in some campaigns, abuse of .NET AppDomainManager hijacking to launch the payload while blending into legitimate software installation or application behavior. Persistence has also been established through Registry Run Key mechanisms.
MINIBIKE command-and-control has been repeatedly described as using cloud infrastructure, especially Microsoft Azure, to blend malicious traffic with legitimate enterprise cloud usage and complicate detection. Across campaigns, operators assigned victim-specific infrastructure and produced uniquely built payloads, reflecting an espionage tradecraft focused on resilience, stealth, and long-term access rather than disruptive effects. MINIBIKE formed an early core implant in this ecosystem before newer related variants such as MiniJunk and MiniBrowse appeared.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MiniBike и MiniBus: RAT-семейства кампании Dream Job. Unit 42 классифицировала шесть обнаруженных RAT-вариантов в два семейства. MiniBike - четыре варианта, развёрнутые двумя координированными волнами.
MiniBike и MiniBus: RAT-семейства кампании Dream Job. Unit 42 классифицировала шесть обнаруженных RAT-вариантов в два семейства. MiniBike - четыре варианта, развёрнутые двумя координированными волнами.
"MINIBIKE (aka SlugResin), a known C++ backdoor that gathers system information and fetches additional payloads..."
Iranian groups deploy MINIBIKE, TWOSTROKE, DEEPROOT, and CRASHPAD in Dream Job-style campaigns...
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Both state-sponsored actors and financially-motivated hackers mostly leveraged compromised identities
The websites would eventually lead to downloading a malicious payload.
Tortoiseshell is described as “targeting supply chains”; Curious Serpens attacked “through phishing and supply chain compromises.”
"Each potential victim receives unique login credentials in advance through spear-phishing communications."
Цепочка заражения начинается с целевого фишинга через рекрутинговые приманки - адаптированный под конкретные должности вариант Dream Job кампании.
This suspected UNC1549 campaign uses two primary methods to achieve initial access to the targets: spear-phishing and credential harvesting. A typical chain of attack consists of several stages: Spear-phishing emails or social media correspondence, disseminating links to fake websites containing Israel-Hamas related content or fake job offers.
actors linked to Iran and China, who maintained access to the victim environment well over a year and a half
MINIBIKE ... provides a full backdoor functionality, including ... running additional processes. MINIBUS provides a more flexible code-execution and command interface, including the ability to run an executable.
При запуске setup.exe из Hiring Portal.zip открывается поддельное окно ошибки с заголовком "Hiring Portal.zip". Пользователь видит ожидаемое поведение - "портал не загрузился" - и не замечает, что payload уже крутится в фоне.
The tools continuously evolve to remain covert, leveraging valid digital signatures, inflate binary sizes, and use multi-stage sideloading and heavy, compiler‑level obfuscation
A benign lure in the form of an application like OneDrive (MINIBIKE) or, in the case of MINIBUS, a custom application presenting content related to Israelis kidnapped by Hamas... Using domain naming schemes that include strings that would likely seem legitimate to network defenders.
Both state-sponsored actors and financially-motivated hackers mostly leveraged compromised identities
Payload installation and device compromise, achieved after the MINIBIKE or MINIBUS backdoors establish C2 communication, in most cases via Microsoft Azure cloud infrastructure.
MINIBIKE is a custom backdoor written in C++ capable of file exfiltration and upload...
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT family used in the UNC1549/Screening Serpens Dream Job espionage campaign. It is delivered via job-lure phishing, uses DLL sideloading and AppDomainManager hijacking for execution and defense evasion, persists via Registry Run Keys, communicates with C2 over HTTPS to Azure-hosted domains, and later variants added chunked file exfiltration.
Backdoor previously deployed by Nimbus Manticore in attacks against aviation and defense organizations across the Middle East.
Backdoor malware used to maintain long-term access in a victim environment and facilitate theft of nearly one terabyte of proprietary data.
Backdoor family delivered via spear-phishing (including job-themed lures) and leveraging cloud infrastructure (e.g., Azure) for C2; used in supply-chain-oriented espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.