Nimbus Manticore, an Iranian APT group, has intensified its campaign against European defense, telecommunications, and aviation sectors using sophisticated spear-phishing and custom malware. The group employs advanced techniques such as multi-stage DLL sideloading, heavy obfuscation, and legitimate code signing to evade detection. Their evolving toolset, including the MiniJunk backdoor and MiniBrowse stealer, demonstrates a high level of operational security and resilience.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Check Point Research published findings on the campaign, attributing the activity to Nimbus Manticore and detailing the fake job portal lures, malware chain, European targeting, and infrastructure changes. The report brought together the new malware families, victimology, and links to related clusters.
Researchers identified a separate but related activity cluster using a dxgi.dll hijack chain and simpler obfuscation, but sharing code with MiniJunk. This suggested that multiple operators may be using a common Nimbus Manticore-linked toolkit.
Check Point reported a recent increase in targeting of Western Europe, especially Denmark, Sweden, and Portugal, while the group continued operations against Middle East targets. Victims included job-seeking professionals in aerospace, defense manufacturing, telecommunications, and critical infrastructure sectors.
Researchers found the group evolved from the earlier Minibike/SlugResin implant to a new toolset including the MiniJunk backdoor and MiniBrowse browser credential stealer. The malware uses DLL sideloading, obfuscation, rotating HTTPS command-and-control, and theft of Chrome and Edge credentials.
An Iran-linked threat actor tracked as Nimbus Manticore conducted a long-running espionage campaign impersonating recruiters and career portals to target aerospace, defense, telecom, and related professionals in Europe and the Middle East. The activity overlaps with tracking names UNC1549, Smoke Sandstorm, and the previously documented 'Iranian Dream Job' campaign.
In June 2025, the operators updated their infrastructure to blend Cloudflare fronting with Microsoft Azure App Service hosting to improve resilience, credibility, and evasion. Researchers also noted use of career-themed domains and valid SSL.com code-signing certificates to support the operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 75 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
12 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourceindustrialcyber.co
Open sourcego.theregister.com
Open sourceresearch.checkpoint.com
Open sourceoutpost24.com
Open sourcesocket.dev
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.