Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
Check Point says Nimbus Manticore used phishing, trojanized installers, and SEO poisoning to spread new malware. The group also appears to have used AI to speed up development.
Intelligence analysis by GPT-5.4 Mini
The article says an IRGC-linked Iranian group broadened its playbook after the February 2026 conflict, moving from career-themed lures to fake meeting invites and search-engine poisoning. Its new MiniFast backdoor and updated MiniJunk variant were used against targets in the U.S., Europe, the Middle East, and elsewhere.
A hacker group linked to Iran changed how it sneaks malware onto computers. Instead of using only fake job offers, it also used fake meeting invites and fake download pages that showed up in search results.
One of its new tools, called MiniFast, works like a remote control. It can tell a computer to open files, run commands, hide itself, and send stolen information back to the attacker.
The report says the group may have used AI to help write the malware faster. That matters because it means bad software can be built and changed more quickly, like a thief getting a better lockpick kit overnight.
Analysis
What changed
Check Point attributes the activity to Nimbus Manticore, a threat group also tracked as Screening Serpens and UNC1549. The group is linked to Iran’s IRGC and has long gone after defense, aviation, and telecom targets with job-themed phishing. The new campaign is broader: it hit aviation and software organizations in the U.S., Europe, and the Middle East after the late-February 2026 joint U.S.-Israeli military campaign against Iran.
New delivery paths
The reporting describes a clear shift in tradecraft across several waves. In February, the group used AppDomain hijacking to load MiniJunk from a ZIP archive hosted on OnlyOffice. In March, the same basic technique was paired with a trojanized Zoom installer, which is suspected to have been part of a fake meeting-invitation lure. In April, the group moved to SEO poisoning, pushing a fake Oracle SQL Developer download site to search results and serving a weaponized installer from a bogus domain, getsqldeveloper[.]com.
MiniFast and the operator model
MiniFast, also called MiniUpdate, is presented as a full backdoor for persistence and remote execution. It uses HTTP to pull tasks, upload results, exfiltrate files, and fetch extra payloads. Before tasking starts, it sends basic system data back to the operator. Supported actions include file handling, directory listing, process enumeration, command execution through cmd.exe, killing processes by PID, DLL loading, ZIP creation, scheduled-task persistence, and privilege escalation via runas. It also lets operators change polling interval and jitter.
Check Point says the code looks unusually structured for such simple malware, with repetitive naming, detailed debug messages, and defensive error handling that suggest AI-assisted development. Unit 42 separately reported MiniUpdate and MiniJunk V2 activity against entities in the U.S., Israel, the UAE, and the wider Middle East, including a U.S. oil and gas firm.
Key points
- Nimbus Manticore used phishing, trojanized installers, and SEO poisoning in separate attack waves.
- Check Point says the group deployed a new backdoor called MiniFast, also tracked as MiniUpdate.
- The malware appears to have been developed with AI help, based on its code structure and debug behavior.
- A fake SQL Developer download page and dozens of linked domains were used to push the lure higher in search results.
- Unit 42 reported related MiniUpdate and MiniJunk V2 activity against targets in multiple countries.



