Iran-linked threat actor Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is attributed to a new intrusion campaign that targets organizations in the aviation and software sectors. According to reporting, the attackers use phishing lures impersonating relevant entities to entice victims into interacting with malicious content. The campaign also reportedly relies on SEO poisoning, where search-engine results are manipulated to direct users to attacker-controlled pages.
Multiple sources describe the deployment of malware components referred to as MiniFast and MiniJunk V2. The backdoor functionality is characterized as being delivered after initial access through the phishing and SEO-poisoning routes. Victims are said to be targeted across the United States, Europe, and the Middle East.
One report links the timing of the campaign to geopolitical context, noting activity following a joint U.S.-Israeli military operation against Iran in late February 2026. The reporting emphasizes attribution to a state-sponsored actor, but it does not indicate any public breach details beyond the delivery of the malware and the targeting focus.