An Iran-linked threat group tracked as Screening Serpens—also known as UNC1549, Smoke Sandstorm, and Iranian Dream Job—ran coordinated cyberespionage operations against organizations in the United States, Israel, the United Arab Emirates, and likely two additional Middle Eastern targets. The activity, observed between February and April 2026, relied on highly tailored recruitment- and meeting-themed social engineering aimed largely at technology-sector professionals as regional tensions escalated in the Middle East.
Researchers said the group deployed six new remote-access trojan variants across two malware families, MiniUpdate and MiniJunk V2, using DLL sideloading and Azure-hosted command-and-control infrastructure dedicated to individual targets or malware variants. A notable shift in tradecraft was the use of AppDomainManager hijacking in .NET applications, allowing the attackers to disable ETW and other security controls through legitimate configuration files before the host application launched. MiniUpdate supported command execution, DLL loading, process control, file theft, UAC elevation, and scheduled-task persistence, while MiniJunk V2 used staged loaders, junk padding, and heavy obfuscation to hinder analysis and detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Nextron attributed a campaign to Nimbus Manticore in which attackers impersonated an Ebix recruiter on LinkedIn and directed aerospace and defense professionals in the Middle East and Europe to a fake hiring portal at ebix[.]recruitment-flow[.]com. Victims were prompted to download a fake two-factor authentication app that launched a multi-stage sideloading chain using AppDomain hijacking, Azure-hosted C2, scheduled-task persistence, and a native implant with anti-analysis and data-exfiltration capabilities.
Check Point Research reported that the IRGC-affiliated actor Nimbus Manticore, also tracked as UNC1549, resurfaced during the 2026 Iranian conflict with upgraded operations targeting aviation and software-sector victims in the United States, Europe, and the Middle East. The report said the actor introduced a new backdoor called MiniFast to replace the previously documented MiniJunk family and used delivery methods including SEO poisoning, a trojanized Zoom installer, fake job lures, and malicious download sites.
Palo Alto Networks Unit 42 publicly reported on the February-April 2026 espionage campaigns, linking them to Screening Serpens and describing the group's increased technical sophistication and operational resilience. The report advised defenders to prioritize detection of DLL sideloading and AppDomainManager hijacking over reliance on known indicators alone.
Unit 42 reported that the group evolved its tradecraft by using AppDomainManager hijacking in .NET applications. This let the malware disable ETW and other security mechanisms through legitimate configuration files before the host application started.
During the 2026 campaigns, researchers identified six new RAT variants grouped into the MiniUpdate and MiniJunk V2 malware families. The malware used DLL sideloading and dedicated Azure-hosted command-and-control infrastructure for each target or variant.
Between February and April 2026, the Iran-linked group Screening Serpens targeted entities in the United States, Israel, the United Arab Emirates, and likely two additional Middle Eastern organizations. The campaigns primarily used tailored recruitment- and meeting-themed social engineering lures aimed at technology-sector professionals.
Unit 42 said Screening Serpens' 2026 espionage activity aligned with the onset of a regional Middle East conflict. The conflict began on Feb. 28, 2026 and provided the broader context for the campaigns that followed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceresearch.checkpoint.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.