MiniFast, also known as MiniUpdate and Retrograde, is a 64-bit Windows backdoor attributed to the Iranian IRGC-affiliated threat actor Nimbus Manticore (UNC1549). It emerged in 2026 as a replacement for MiniJunk in espionage campaigns targeting aviation and software-sector organizations in the United States, Europe, the Middle East, Saudi Arabia, and Australia. MiniFast is deployed through career-themed spearphishing, trojanized installers abusing AppDomain hijacking, and SEO-poisoned websites impersonating legitimate software-download portals. The malware establishes long-term access through scheduled-task persistence and communicates with command-and-control infrastructure over HTTP using structured JSON-based tasking while impersonating Chrome browser traffic. It performs host reconnaissance; enumerates processes, drives, and directories; executes shell commands; manages, uploads, and downloads files; loads DLLs; creates archives; terminates processes; adjusts beacon timing; and can request elevation through Windows runas. Analyses have identified coding characteristics consistent with possible AI-assisted development, although this is an assessment rather than a confirmed development provenance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
L’attribution à Mirage Kitten repose sur des similarités structurelles avec le backdoor natif Retrograde/MiniFast.
Attribution of PollCat to Nimbus Manticore is supported by structural, command-fetching, beacon-timing, and command-set similarities between PollCat and MiniFast, a backdoor previously attributed to the group.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
For the first time, we observed the use of SEO poisoning as an additional malware delivery method... the actor abuses search engine optimization techniques by registering dozens of domains that link to the bogus domain, getsqldeveloper[.]com.
Check Point said Nimbus Manticore has shifted tactics in its most recent attacks... using search engine optimization (SEO) poisoning to impersonate the software Oracle SQL Developer and spread MiniFast... Keyword stuffing of phrases such as “download SQL Developer” and “SQL Developer free” was also used to help the fake website surface high in search results for engines such as Bing and DuckDuckGo.
Both waves of attacks utilized career-themed phishing lures for initial access... As in previous attacks, Nimbus Manticore used career-themed phishing lures to spread MiniFast during Operation Epic Fury, specifically impersonating a U.S. domestic airline. Victims were lured to install a trojanized version of the legitimate Zoom installer after clicking a fake meeting invitation link.
The installer was not a crude knockoff; it demonstrated detailed knowledge of the legitimate Zoom installation process, even monitoring for the creation of a specific scheduled task that Zoom normally generates during setup, then silently hijacking that task to establish persistence without triggering obvious alarms.
It then monitors for the creation of a scheduled task — a part of the legitimate Zoom installation process — and modifies this task to load the second-stage components... Prior to executing the payload, the loader ensures that the hosting process name is update.exe and the parent process is svchost.exe to maintain stealth and persistence via the scheduled task... The backdoor supports commands for a wide range of actions including... creation of an additional scheduled task.
The backdoor supports commands for a wide range of actions including file and folder management and exfiltration, file download from the C2, shell command execution...
The installer was not a crude knockoff; it demonstrated detailed knowledge of the legitimate Zoom installation process, even monitoring for the creation of a specific scheduled task that Zoom normally generates during setup, then silently hijacking that task to establish persistence without triggering obvious alarms.
It then monitors for the creation of a scheduled task — a part of the legitimate Zoom installation process — and modifies this task to load the second-stage components... Prior to executing the payload, the loader ensures that the hosting process name is update.exe and the parent process is svchost.exe to maintain stealth and persistence via the scheduled task... The backdoor supports commands for a wide range of actions including... creation of an additional scheduled task.
The installer was not a crude knockoff; it demonstrated detailed knowledge of the legitimate Zoom installation process, even monitoring for the creation of a specific scheduled task that Zoom normally generates during setup, then silently hijacking that task to establish persistence without triggering obvious alarms.
It then monitors for the creation of a scheduled task — a part of the legitimate Zoom installation process — and modifies this task to load the second-stage components... Prior to executing the payload, the loader ensures that the hosting process name is update.exe and the parent process is svchost.exe to maintain stealth and persistence via the scheduled task... The backdoor supports commands for a wide range of actions including... creation of an additional scheduled task.
The loader itself is lightly obfuscated. Most readable strings are decrypted at runtime using a simple combination of ROT13 encoding and reversed-string transformations.
Victims were lured to install a trojanized version of the legitimate Zoom installer... AppDomain hijacking is again used to load the second-stage loader Updater.dll via the Setup.exe binary — now renamed to Update.exe... The malware impersonates a Chrome browser user agent to blend in with legitimate traffic.
At the beginning of its execution, the loader performs a simple anti-analysis validation intended to evade sandbox environments and automated dynamic analysis systems. The malware only continues execution if: The hosting process name is update.exe The parent process is svchost.exe
Before entering its tasking loop, the malware performs basic host reconnaissance by collecting information such as the username, hostname, and domain info.
The commands supported by the backdoor are varied, enabling file operations, directory listings, process enumeration
MiniFast performs system reconnaissance and then awaits commands from the C2 server...
The commands supported by the backdoor are varied, enabling file operations, directory listings
At the beginning of its execution, the loader performs a simple anti-analysis validation intended to evade sandbox environments and automated dynamic analysis systems. The malware only continues execution if: The hosting process name is update.exe The parent process is svchost.exe
MiniFast, the successor of MiniJunk, enables extensive control of the victim’s machine through API-based communications with the attacker’s command-and-control (C2) server... MiniFast performs system reconnaissance and then awaits commands from the C2 server, transmitting data in the JSON format. The malware impersonates a Chrome browser user agent to blend in with legitimate traffic.
NodeRabbit... connects to infrastructure hosted on Azure... PollCat starts running and begins talking to its command server the moment the application loads.
La variante Égypte prend en charge les proxys NTLM/Negotiate via curl.exe; cette délégation proxy est aussi citée comme similarité avec Retrograde/MiniFast.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously attributed Nimbus Manticore backdoor used as a comparative reference supporting PollCat attribution. The content does not provide additional capability details.
A native DLL backdoor cited as a historical Mirage Kitten tool. It is referenced for structural similarities to PollCat's C2 protocol, command identifiers, persistence behavior, and proxy-authentication design.
Native backdoor referenced alongside Retrograde as attribution context for the campaign. It shares C2 and operational characteristics with the newly documented NodeRabbit and PollCat malware, including an HTTP 400/socketId handshake pattern, beacon timing, and command similarities.
A malware/tool family mentioned only for functional comparison with BridgeHead.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.