PULSE NAME
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict
WHITE Nimbus Manticore AlienVault 2026-05-25 Modified: 2026-05-25
69
IOCs
HIGH VOLUME
The Iranian IRGC-affiliated threat actor Nimbus Manticore launched sophisticated cyber operations during Operation Epic Fury, the US military campaign against Iran beginning February 28, 2026. The campaigns targeted organizations in aviation and software sectors across the United States, Europe, and Middle East using career-themed phishing lures. For the first time, the actor employed SEO poisoning techniques and introduced MiniFast, a previously undocumented backdoor showing signs of AI-assisted development. The operations leveraged AppDomain hijacking and abused legitimate Zoom installer execution flows for malware deployment. The actor demonstrated rapid adaptation capabilities during wartime conditions, maintaining high operational availability while expanding targeting to US-based aviation companies. Multiple campaign waves were observed from February through April 2026, with persistent infrastructure and evolving techniques.
Indicators of Compromise (19 / 69 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 00213937e9c41e69bed025a882de521b 2026-05-25
FileHash-MD5 1004a0df8dd34741b40ed6bc3c04ade5 2026-05-25
FileHash-MD5 1274eb21a996552f2bba7ed949f66c02 2026-05-25
FileHash-MD5 16b421555b84b87e82a56813e86dbf80 2026-05-25
FileHash-MD5 2d3fcf0f7a069958a7d9ab2d9d52bee7 2026-05-25
FileHash-MD5 3106848925a39b9d51f9ad9f5963e417 2026-05-25
FileHash-MD5 34af888f33898a4c3b93ac0e8fecf3a2 2026-05-25
FileHash-MD5 36e3cd7b35f5abdf8b5f76afb46e4dea 2026-05-25
FileHash-MD5 628d831989787ee1b4ffee611cb2014b 2026-05-25
FileHash-MD5 6bba585b1377068865cb07b1d882cf3d 2026-05-25
FileHash-MD5 756d53fb230a482568d46da68548227c 2026-05-25
FileHash-MD5 810f8e3b88eb05f710c09552941d6f56 2026-05-25
FileHash-MD5 8d1f16c615b39b13ddfe5d2820c6bae8 2026-05-25
FileHash-MD5 8eb107b3dde0a7ac039c668b427a3634 2026-05-25
FileHash-MD5 9ef9afb9821cbe7e77191b13a7948a2d 2026-05-25
FileHash-MD5 cdbe76cdfdec8f7c09781b2ef0fdb7f4 2026-05-25
FileHash-MD5 d6cfee4032ba6f8737242fbbe2ec87d7 2026-05-25
FileHash-MD5 ece99a279b8c48271b000c620d291c6a 2026-05-25
FileHash-MD5 ef0b3833f96b9b5dfe2fc91ec7ba0727 2026-05-25