Iranian Hackers: Unveiling the MiniFast & MiniJunk V2 Cyberattacks (2026)

Iranian Hackers Deploy MiniFast and MiniJunk V2: A Deep Dive into the Evolving Tactics of Nimbus Manticore

The Iranian state-sponsored threat actor, Nimbus Manticore, has been making headlines with its evolving tactics and the deployment of new malware. This group, known for targeting defense, aviation, and telecommunication sectors, has recently been linked to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East.

What makes this campaign particularly intriguing is the use of a new backdoor codenamed MiniFast (aka MiniUpdate), which appears to have been developed with the assistance of artificial intelligence (AI). This development raises questions about the capabilities and motivations of Iranian state-sponsored actors.

The Evolution of Nimbus Manticore's Tactics

Nimbus Manticore, affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been known for targeting defense, aviation, and telecommunication sectors using career-themed phishing lures. These campaigns have been codenamed the Iranian Dream Job, owing to tactical similarities with Operation Dream Job orchestrated by North Korean hackers.

Recent attack chains linked to the threat actor have witnessed a shift in tradecraft. In February 2026, they used AppDomain hijacking to deliver MiniJunk, followed by the deployment of the MiniFast backdoor in March and a reliance on SEO poisoning to distribute a trojanized version of Oracle's SQL Developer software in April.

The Role of AI in MiniFast Development

There are signs that Nimbus Manticore used AI-assisted development to help create MiniFast. This includes excessive error handling and defensive programming logic, repetitive function and method naming patterns with descriptive or verbose identifiers, several detailed error-reporting strings and debug-style status messages, and modular code organization despite the malware's overall simplicity.

The MiniFast Backdoor

MiniFast is described as a fully featured backdoor designed for long-term persistence and remote command execution. It communicates with a remote server over HTTP requests to fetch tasks, upload command execution results, exfiltrate files, and download additional payload from the server. Before entering the tasking loop, the malware also beacons basic system information to the operator.

The commands supported by the backdoor are varied, enabling file operations, directory listings, process enumeration, command execution via "cmd.exe," process termination using its PID, DLL loading, ZIP archive creation, persistence via scheduled tasks, and privilege escalation via the "runas" command.

The backdoor also supports the ability to update the polling interval and jitter value applied to beacon intervals so as to randomize the frequency with which commands are retrieved from the server.

The Impact of the Campaign

The disclosure coincides with a report from Palo Alto Networks Unit 42 about the threat actor's targeting of entities in the U.S., Israel, the United Arab Emirates, and the Middle East with MiniUpdate and an updated version of MiniJunk called MiniJunk V2. Among those targeted as part of the elaborate espionage scheme was a U.S. oil and gas firm.

The findings show that Iranian threat actors are taking a page out of North Korea's playbook to infiltrate organizations of interest by going after their employees with lucrative job opportunities.

The Broader Implications

The development also comes as Iranian hackers are suspected to have conducted a series of attacks aimed at tank readers at gas stations across multiple states in the U.S. While the incidents did not cause physical damage or harm, they have sparked concerns that such access could potentially cause gas leaks to go undetected or create other risks to critical infrastructure.

Conclusion

The evolving tactics of Nimbus Manticore, including the use of AI-assisted development and the deployment of MiniFast and MiniJunk V2, highlight the sophistication and adaptability of Iranian state-sponsored actors. As the group continues to evolve its tactics, it is crucial for organizations to remain vigilant and proactive in their cybersecurity efforts.

Iranian Hackers: Unveiling the MiniFast & MiniJunk V2 Cyberattacks (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Kimberely Baumbach CPA

Last Updated:

Views: 6464

Rating: 4 / 5 (41 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Kimberely Baumbach CPA

Birthday: 1996-01-14

Address: 8381 Boyce Course, Imeldachester, ND 74681

Phone: +3571286597580

Job: Product Banking Analyst

Hobby: Cosplaying, Inline skating, Amateur radio, Baton twirling, Mountaineering, Flying, Archery

Introduction: My name is Kimberely Baumbach CPA, I am a gorgeous, bright, charming, encouraging, zealous, lively, good person who loves writing and wants to share my knowledge and understanding with you.