Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    SpaceX Market Sizes Are Replatforming – AI and Space Are Replatforming Telecom, IT and Business

    May 27, 2026

    Acer ProDesigner PE160WUT portable monitor review

    May 26, 2026

    YouTube Music’s newest feature should have been there a decade ago

    May 26, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Iranian APT Targets Aviation, Software Companies With Updated Tools
    Iranian APT Targets Aviation, Software Companies With Updated Tools
    Cybersecurity

    Iranian APT Targets Aviation, Software Companies With Updated Tools

    The Tech GuyBy The Tech GuyMay 26, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    An Iranian APT tracked as Nimbus Manticore has adopted new tactics and updated its arsenal in new intrusions targeting aviation and software companies, Check Point reports.

    Advertisement

    Also known as Bohrium, Smoke Sandstorm, TA455, and UNC1549, and active since at least 2022, Nimbus Manticore is believed to be a subgroup of Charming Kitten (APT35) and to have ties with Iran’s Islamic Revolutionary Guard Corps (IRGC).

    Nimbus Manticore was previously seen targeting aerospace, aviation, and defense organizations in the Middle East and Europe with the MiniBike and MiniBus backdoors.

    In November 2024, the group was blamed for adopting North Korea-linked Lazarus Group’s tactics in a Dream Job campaign targeting the aerospace industry.

    Earlier this year, Google warned of the APT’s continuous targeting of organizations in the defense sector with fake job offers, and Check Point now says that the group’s activities have continued during and after the US military campaign against Iran that started in February 2026.

    Amid rising geopolitical tensions in the Middle East, Nimbus Manticore’s phishing campaigns started employing AppDomain hijacking for payload execution, instead of DLL sideloading.

    Advertisement. Scroll to continue reading.

    The technique relies on a trojanized XML .config file placed in the target .NET application’s directory to load a malicious DLL at launch time.

    Nimbus Manticore used a phishing lure resembling previous campaigns, targeting employees at aviation and software companies in Saudi Arabia and Australia to download a compressed ZIP archive from the OnlyOffice platform, leading to infections with a new version of the MiniJunk backdoor.

    In another campaign, the APT used job lures masquerading as a US-based airline, leading to a trojanized Zoom installer. Using AppDomain hijacking, the infection chain led to the deployment of a new backdoor, named MiniFast.

    Deployed as a 64-bit Windows PE DLL, the backdoor impersonates a Chrome browser and was designed for long-term persistence and remote command execution.

    It also allows attackers to manipulate files, exfiltrate files, enumerate processes, terminate processes, manipulate directories, create scheduled tasks, and deploy additional payloads.

    “Nimbus Manticore demonstrated a strong ability to rapidly adapt, maintain infrastructure, and develop new tooling. We assess that this capability was likely supported, at least in part, by LLM-based tools and AI-assisted development techniques,” Check Point notes.

    In April, Nimbus Manticore was seen using a fake SQL Developer download website to distribute the MiniFast backdoor. The campaign abused search engine optimization techniques, relying on dozens of domains linking to the fake website to increase its reputation.

    “At the time of our analysis, the malicious domain ranked high in the results returned by multiple search engines, such as Bing and DuckDuckGo, for the query ‘sql developer’. This increased the likelihood that users searching for legitimate SQL Developer downloads would encounter the site,” Check Point notes.

    While typical Nimbus Manticore operations have focused on the Middle East, Europe, and Africa, mainly targeting Israel and the United Arab Emirates, the fresh campaigns also revealed a shift towards US organizations.

    “Fraudulent hiring portals impersonating aviation companies were used to target employees and organizations operating within that industry. In the current campaign, impersonating US domestic airlines suggests a deliberate focus on US-based targets,” Check Point notes.

    Related: Iranian APT Intrusion Masquerades as Chaos Ransomware Attack

    Related: Iranian Cyber Group Handala Targets US Troops in Bahrain

    Related: Pre-Stuxnet Sabotage Malware ‘Fast16’ Linked to US-Iran Cyber Tensions

    Related: Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

    May 26, 2026

    Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

    May 26, 2026

    266,000 Affected by Data Breach at Radiology Associates of Richmond

    May 26, 2026

    Oncology Institute Discloses Data Breach

    May 25, 2026

    Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

    May 25, 2026

    Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

    May 24, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    SpaceX Market Sizes Are Replatforming – AI and Space Are Replatforming Telecom, IT and Business

    May 27, 2026

    Acer ProDesigner PE160WUT portable monitor review

    May 26, 2026

    YouTube Music’s newest feature should have been there a decade ago

    May 26, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.