An Iran-linked threat group tracked as Screening Serpens—also known as UNC1549, Smoke Sandstorm, and Iranian Dream Job—ran coordinated cyberespionage operations against organizations in the United States, Israel, the United Arab Emirates, and likely two additional Middle Eastern targets. The activity, observed between February and April 2026, relied on highly tailored recruitment- and meeting-themed social engineering aimed largely at technology-sector professionals as regional tensions escalated in the Middle East.
Researchers said the group deployed six new remote-access trojan variants across two malware families, MiniUpdate and MiniJunk V2, using DLL sideloading and Azure-hosted command-and-control infrastructure dedicated to individual targets or malware variants. A notable shift in tradecraft was the use of AppDomainManager hijacking in .NET applications, allowing the attackers to disable ETW and other security controls through legitimate configuration files before the host application launched. MiniUpdate supported command execution, DLL loading, process control, file theft, UAC elevation, and scheduled-task persistence, while MiniJunk V2 used staged loaders, junk padding, and heavy obfuscation to hinder analysis and detection.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Nextron attributed a campaign to Nimbus Manticore in which attackers impersonated an Ebix recruiter on LinkedIn and directed aerospace and defense professionals in the Middle East and Europe to a fake hiring portal at ebix[.]recruitment-flow[.]com. Victims were prompted to download a fake two-factor authentication app that launched a multi-stage sideloading chain using AppDomain hijacking, Azure-hosted C2, scheduled-task persistence, and a native implant with anti-analysis and data-exfiltration capabilities.
Check Point Research reported that the IRGC-affiliated actor Nimbus Manticore, also tracked as UNC1549, resurfaced during the 2026 Iranian conflict with upgraded operations targeting aviation and software-sector victims in the United States, Europe, and the Middle East. The report said the actor introduced a new backdoor called MiniFast to replace the previously documented MiniJunk family and used delivery methods including SEO poisoning, a trojanized Zoom installer, fake job lures, and malicious download sites.
Palo Alto Networks Unit 42 publicly reported on the February-April 2026 espionage campaigns, linking them to Screening Serpens and describing the group's increased technical sophistication and operational resilience. The report advised defenders to prioritize detection of DLL sideloading and AppDomainManager hijacking over reliance on known indicators alone.
Unit 42 reported that the group evolved its tradecraft by using AppDomainManager hijacking in .NET applications. This let the malware disable ETW and other security mechanisms through legitimate configuration files before the host application started.
During the 2026 campaigns, researchers identified six new RAT variants grouped into the MiniUpdate and MiniJunk V2 malware families. The malware used DLL sideloading and dedicated Azure-hosted command-and-control infrastructure for each target or variant.
Between February and April 2026, the Iran-linked group Screening Serpens targeted entities in the United States, Israel, the United Arab Emirates, and likely two additional Middle Eastern organizations. The campaigns primarily used tailored recruitment- and meeting-themed social engineering lures aimed at technology-sector professionals.
Unit 42 said Screening Serpens' 2026 espionage activity aligned with the onset of a regional Middle East conflict. The conflict began on Feb. 28, 2026 and provided the broader context for the campaigns that followed.
Kaspersky attributed the previously undocumented cross-platform NodeRabbit and PollCat RATs, delivered through recruiter-themed coding challenges targeting Middle East and African software engineers, to Iranian-aligned Nimbus Manticore. The assessment links the tooling to the actor's MiniFast/MiniUpdate backdoor and Azure- and Cloudflare-based C2 patterns, identifying a shift toward cross-platform scripting malware.
Mirage Kitten conducted a cyberespionage campaign targeting fintech, aviation, and aerospace developer workstations across the Middle East and Africa, with confirmed NodeRabbit infections in Afghanistan, Egypt, and Ethiopia. The operators used fake recruiter accounts and trojanized coding challenges to deliver the new cross-platform Node.js/JavaScript RATs NodeRabbit and PollCat, including VS Code-extension and Git-hook persistence in a NodeRabbit variant.
Google Chronicle released Emerging Threats detection rules for Enterprise+ customers and made IOCs available through Applied Threat Intelligence in connection with suspected Iranian actor UNC1549 targeting Israeli and Middle Eastern aerospace and defense sectors. The published indicators included numerous Azure Websites and Azure CloudApp hostnames.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 88 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
13 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetherecord.media
Open sourcemalware.news
Open sourcesecurelist.com
Open sourcecybersecuritynews.com
Open sourceresearch.checkpoint.com
Open sourceunit42.paloaltonetworks.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.