Iranian Hackers Deploy MiniFast and MiniJunk V2: A Deep Dive into the Evolving Tactics of Nimbus Manticore
The Iranian state-sponsored threat actor, Nimbus Manticore, has been making headlines with its evolving tactics and the deployment of new malware. This group, known for targeting defense, aviation, and telecommunication sectors, has recently been linked to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East.
What makes this campaign particularly intriguing is the use of a new backdoor codenamed MiniFast (aka MiniUpdate), which appears to have been developed with the assistance of artificial intelligence (AI). This development raises questions about the capabilities and motivations of Iranian state-sponsored actors.
The Evolution of Nimbus Manticore's Tactics
Nimbus Manticore, affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been known for targeting defense, aviation, and telecommunication sectors using career-themed phishing lures. These campaigns have been codenamed the Iranian Dream Job, owing to tactical similarities with Operation Dream Job orchestrated by North Korean hackers.
Recent attack chains linked to the threat actor have witnessed a shift in tradecraft. In February 2026, they used AppDomain hijacking to deliver MiniJunk, followed by the deployment of the MiniFast backdoor in March and a reliance on SEO poisoning to distribute a trojanized version of Oracle's SQL Developer software in April.
The Role of AI in MiniFast Development
There are signs that Nimbus Manticore used AI-assisted development to help create MiniFast. This includes excessive error handling and defensive programming logic, repetitive function and method naming patterns with descriptive or verbose identifiers, several detailed error-reporting strings and debug-style status messages, and modular code organization despite the malware's overall simplicity.
The MiniFast Backdoor
MiniFast is described as a fully featured backdoor designed for long-term persistence and remote command execution. It communicates with a remote server over HTTP requests to fetch tasks, upload command execution results, exfiltrate files, and download additional payload from the server. Before entering the tasking loop, the malware also beacons basic system information to the operator.
The commands supported by the backdoor are varied, enabling file operations, directory listings, process enumeration, command execution via "cmd.exe," process termination using its PID, DLL loading, ZIP archive creation, persistence via scheduled tasks, and privilege escalation via the "runas" command.
The backdoor also supports the ability to update the polling interval and jitter value applied to beacon intervals so as to randomize the frequency with which commands are retrieved from the server.
The Impact of the Campaign
The disclosure coincides with a report from Palo Alto Networks Unit 42 about the threat actor's targeting of entities in the U.S., Israel, the United Arab Emirates, and the Middle East with MiniUpdate and an updated version of MiniJunk called MiniJunk V2. Among those targeted as part of the elaborate espionage scheme was a U.S. oil and gas firm.
The findings show that Iranian threat actors are taking a page out of North Korea's playbook to infiltrate organizations of interest by going after their employees with lucrative job opportunities.
The Broader Implications
The development also comes as Iranian hackers are suspected to have conducted a series of attacks aimed at tank readers at gas stations across multiple states in the U.S. While the incidents did not cause physical damage or harm, they have sparked concerns that such access could potentially cause gas leaks to go undetected or create other risks to critical infrastructure.
Conclusion
The evolving tactics of Nimbus Manticore, including the use of AI-assisted development and the deployment of MiniFast and MiniJunk V2, highlight the sophistication and adaptability of Iranian state-sponsored actors. As the group continues to evolve its tactics, it is crucial for organizations to remain vigilant and proactive in their cybersecurity efforts.