Nimbus Manticore Drops MiniFast and MiniJunk V2 in Aviation Phishing Wave

Iran-linked UNC1549 is back with refreshed loaders, SEO-poisoned lures, and aviation-themed bait aimed at U.S., European, and Gulf targets.

ThreatVectr Newsdesk· 3 min read
Nimbus Manticore Drops MiniFast and MiniJunk V2 in Aviation Phishing Wave
Share

This one stings if you run hiring portals or vendor logins for aerospace, defense subcontracting, or aviation software. The Iranian state-aligned crew tracked as Nimbus Manticore (also called UNC1549 and Screening Serpens) has restarted operations against firms in the U.S., Europe, and the Middle East, leaning on impersonated aviation and software brands to push two updated implants: MiniFast and MiniJunk V2. The activity escalated after the joint U.S.-Israeli military operation against Iran in late February 2026.

The playbook will look familiar if you tracked UNC1549 through 2024. Fake recruiter outreach, lookalike careers portals, and now SEO poisoning that pushes attacker-controlled job boards into the top results when an engineer searches for a niche aviation employer. Click through, fill in your details, and you get served a tailored payload instead of a callback from HR.

MiniFast is the lighter first-stage. It does enough to fingerprint the host and pull the heavier MiniJunk V2 loader, which has been reworked to fold in junk code, control-flow obfuscation, and a chain of API hashing tricks that defeat naive signature matching. Once resident, the implant gives the operator credential theft and a foothold suitable for handoff to the group's longer-running espionage tooling.

What is new is the targeting tempo. Earlier UNC1549 waves were patient and narrow. This round is wider, faster, and more willing to burn infrastructure (a sign the operators care about volume of accesses right now, not stealth). Aviation suppliers and the small software shops that sell into them are taking the brunt.

The lures are well-made. Your junior engineers are the soft target here, not your SOC. Recruiter emails referencing real open requisitions, PDFs that match the impersonated company's brand kit, and landing pages hosted on domains registered weeks in advance. And the SEO-poisoned results bypass email controls entirely.

A few things worth noting if you are a defender at a mid-size aerospace supplier. The group reuses living-off-the-land patterns more than custom malware. EDR telemetry on rundll32, regsvr32, and signed-binary proxy execution will catch more than YARA will. Block execution from user-writable paths.

Short window to act.

Defender checklist — do these this week:

  1. Search proxy and DNS logs for outbound connections to newly registered domains impersonating your aviation customers or vendors over the last 60 days.
  2. Force MFA on every careers, HR, and applicant-tracking portal, and disable legacy auth on the Microsoft 365 tenants that back them.
  3. Push an EDR rule blocking script-host and signed-LOLBin execution from %TEMP%, %APPDATA%, and user Downloads folders.
  4. Brief recruiters and engineering managers on the recruiter-impersonation pattern. Give them a single internal channel to verify suspicious outreach.
  5. Add SEO-poisoned job-board domains to your threat-intel ingest and alert on first-seen resolutions inside your network.
© 2026 Threat Vectr