Screening Serpens
Iranian state-sponsored (IRGC-linked) · Espionage / intelligence collection / regional conflict intelligence
Tactics, Techniques & Procedures (TTPs)
- Personalised spear-phishing themed around aerospace and defence job listings ("Iranian Dream Job" approach)
- MiniUpdate and MiniJunk V2 RAT families — six new variants documented in 2026
- AppDomainManager hijacking for EDR bypass: malicious .NET assembly loaded during application startup before endpoint tooling hooks
- Azure-hosted C2 infrastructure — dedicated domain clusters per intrusion set to prevent cross-contamination
- DLL sideloading alongside legitimate signed executables for payload delivery
- Operational tempo surge timed to regional conflict escalation (from February 2026)
Known Targets
Analyst Notes
Iran-nexus APT tracked by Palo Alto Networks Unit 42 as Screening Serpens and by Mandiant as UNC1549; shares infrastructure and tradecraft with Smoke Sandstorm. Unit 42 documented six new RAT variants (MiniUpdate, MiniJunk V2 families) deployed in a campaign wave between February and April 2026 — directly correlated with the escalation of regional conflict from 28 February 2026. The AppDomainManager hijacking technique is specifically engineered to execute before EDR products initialise their hooks, making it effective against organisations with modern endpoint security tooling. Spear-phishing lures impersonating a major commercial airline and defence sector employers demonstrate investment in personalised social engineering at scale. See also: UNC1549 (Screening Serpens / Nimbus Manticore) profile.
Also Known As