Actor Profile

Nimbus Manticore (also tracked as Screening Serpens and UNC1549) is an Iranian state-sponsored threat actor attributed to Iran's intelligence apparatus. The group's operational tempo and targeting align with Iranian strategic interests, particularly in response to geopolitical tensions. Motivated by intelligence collection and potential pre-positioning for disruptive operations, Nimbus Manticore focuses on sectors critical to national security and economic infrastructure. The group demonstrates moderate technical sophistication with a preference for social engineering-based initial access vectors and custom malware tooling.

TTPs (Tactics, Techniques, Procedures)

Nimbus Manticore employs phishing campaigns for initial access, likely leveraging spearphishing attachments or links (T1566). The group utilizes SEO poisoning techniques to manipulate search engine results and deliver malicious payloads, indicating watering hole or drive-by compromise tactics (T1189, T1608.004). The deployment of custom malware families MiniFast and MiniJunk V2 suggests capabilities in command and control (T1071), persistence mechanisms, and potential data exfiltration. The dual-malware approach indicates operational redundancy and diverse post-compromise objectives, potentially including reconnaissance, credential harvesting, and establishing persistent access within victim networks.

Targets & Patterns

Nimbus Manticore targets the aviation and software sectors, with observed activity spanning the United States, Europe, and the Middle East. The aviation sector represents critical infrastructure with intelligence value related to logistics, defense contracting, and transportation security. Software sector targeting suggests supply chain compromise objectives or theft of intellectual property and source code. The geographic distribution reflects Iranian intelligence priorities: U.S. targets align with long-standing adversarial relations, European targets may support sanctions evasion or technology acquisition, and Middle East operations likely focus on regional rivals and monitoring adversary capabilities. The timing following February 2026 military tensions indicates reactive tasking driven by escalated geopolitical conflict.

Historical Context

This campaign represents a continuation of Iranian state-sponsored cyber operations targeting Western critical infrastructure and technology sectors. The use of multiple aliases (Screening Serpens, UNC1549) reflects tracking by different security vendors, with UNC designation indicating Mandiant/Google attribution. Iranian APT groups have historically leveraged geopolitical events as operational triggers, with increased activity following military confrontations, sanctions, or regional conflicts. The deployment of custom malware families (MiniFast, MiniJunk V2) follows established Iranian tradecraft of developing bespoke tooling rather than relying solely on commodity malware. SEO poisoning as an initial access vector has been observed in previous Iranian campaigns, demonstrating evolution from traditional spearphishing toward more scalable compromise methods.

Defensive Recommendations

  • Monitor for SEO poisoning indicators by tracking unexpected search engine referrals to corporate assets and analyzing web traffic patterns for anomalous user-agent strings or geographic origins inconsistent with legitimate business operations
  • Implement enhanced email security controls including DMARC, SPF, and DKIM validation, combined with user awareness training focused on identifying phishing lures related to current geopolitical events and industry-specific themes
  • Deploy behavioral analytics to detect MiniFast and MiniJunk V2 post-compromise activity, focusing on unusual outbound network connections, abnormal process execution chains, and lateral movement patterns (T1071, T1021)
  • Harden aviation and software development environments with network segmentation, privileged access management, and enhanced logging for critical systems to limit lateral movement and detect reconnaissance activity
  • Establish threat hunting procedures targeting Iranian TTPs, including searches for SEO poisoning infrastructure, known Nimbus Manticore phishing themes, and indicators of custom malware deployment in aviation and software sector networks

---

# Geopolitical Context

Geopolitical Context

The campaign attributed to Nimbus Manticore (also tracked as Screening Serpens and UNC1549) appears consistent with Iranian state-sponsored cyber operations that typically intensify following regional military escalations. The timing—following reported military tensions in February 2026—suggests the activity may be part of a broader intelligence collection effort aimed at strategic sectors. Aviation and software targets align with Tehran's historical focus on critical infrastructure reconnaissance and supply chain positioning. The geographic spread across the United States, Europe, and the Middle East indicates a multi-theater approach, likely reflecting Iran's strategic interests in monitoring adversary capabilities and maintaining asymmetric options during periods of heightened geopolitical friction.

State Actor Alignment

Nimbus Manticore is assessed by multiple threat intelligence vendors to have links to Iranian state interests. The deployment of custom tooling (MiniFast and MiniJunk V2) and the targeting pattern are consistent with tasking priorities observed in previous campaigns attributed to Iranian cyber units. While direct organizational attribution remains opaque, the operational tempo and sector focus suggest alignment with Islamic Revolutionary Guard Corps (IRGC) or Ministry of Intelligence and Security (MOIS) objectives. U.S. and European sanctions frameworks targeting Iranian cyber actors may apply, depending on confirmed attribution and impact assessments by national authorities.

Business Impacty pro region

For Europe, the campaign underscores persistent exposure to Iranian cyber operations, particularly in dual-use technology and transportation sectors that support both civilian and defense supply chains. European aviation firms with ties to Middle Eastern markets or defense contracts may face elevated risk. In the Middle East, the activity likely reflects Iran's effort to monitor regional adversaries and coalition partners amid ongoing security dynamics. For the United States, targeting of aviation and software sectors raises concerns about potential pre-positioning for disruptive operations or intellectual property theft that could erode competitive advantages in aerospace and technology domains. The cross-regional nature of the campaign may prompt coordinated defensive measures and information-sharing through NATO, the EU, and bilateral channels.

Forecast

If military tensions persist or escalate in the coming months, Iranian-linked cyber activity targeting critical infrastructure and strategic sectors is likely to intensify, with potential expansion to energy, telecommunications, and defense industrial base entities. Should diplomatic efforts reduce friction, operational tempo may decrease but is unlikely to cease entirely, given Iran's reliance on cyber capabilities for strategic intelligence and asymmetric leverage. If attribution is formalized by U.S. or allied governments, additional sanctions designations or public advisories may follow, potentially prompting tactical shifts in tradecraft. Organizations in affected sectors should anticipate sustained phishing and SEO poisoning campaigns and prioritize detection of custom malware families associated with this cluster of activity.