Skip to content
← All Threat Actors
Nation-State high Iran

Nimbus Manticore

Iranian state-sponsored (IRGC) · Espionage / intelligence collection

Reports 1
Active Since 2022
Last Reported 25 May 2026
Sectors Targeted transport, communications, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Career-themed spear-phishing with fake job offers from defence industry personas
  • MiniFast backdoor (LLM-assisted development -- rapid iteration capability)
  • AppDomain Hijacking for stealthy .NET code injection (replaces DLL sideloading)
  • SEO poisoning for malware delivery -- trojanised software installers (Oracle SQL Developer lure)
  • DLL sideloading alongside legitimate signed executables (legacy delivery)
  • Credential collection, file staging, and command execution via backdoor

Known Targets

European aviation operators (carriers, MRO providers, air traffic control)Western European telecommunications operatorsAerospace and defence contractors and supply chainCritical infrastructure (Israel, Gulf states, Turkey, Western Europe)

Analyst Notes

Tracked by Mandiant as UNC1549, linked to IRGC intelligence collection operations. Historically focused on aerospace and defence across Israel, the Gulf states, and Turkey. Following the US-Iran conflict that began February 2026 (Operation Epic Fury), the group dramatically accelerated its tempo: new backdoor (MiniFast), two new delivery techniques, and significantly expanded European targeting within a three-month window. The SEO poisoning delivery channel bypasses email security controls entirely -- no prior contact with targets required. The pace of retooling indicates direction to collect rapidly while the conflict window is open.

Also Known As

UNC1549Smoke Sandstorm (shared infrastructure and tradecraft)