PULSE NAME
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict
WHITE Nimbus Manticore AlienVault 2026-05-25 Modified: 2026-05-25
69
IOCs
HIGH VOLUME
The Iranian IRGC-affiliated threat actor Nimbus Manticore launched sophisticated cyber operations during Operation Epic Fury, the US military campaign against Iran beginning February 28, 2026. The campaigns targeted organizations in aviation and software sectors across the United States, Europe, and Middle East using career-themed phishing lures. For the first time, the actor employed SEO poisoning techniques and introduced MiniFast, a previously undocumented backdoor showing signs of AI-assisted development. The operations leveraged AppDomain hijacking and abused legitimate Zoom installer execution flows for malware deployment. The actor demonstrated rapid adaptation capabilities during wartime conditions, maintaining high operational availability while expanding targeting to US-based aviation companies. Multiple campaign waves were observed from February through April 2026, with persistent infrastructure and evolving techniques.
Indicators of Compromise (19 / 69 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0997b6c2fdc3af2de118db559c92ef510c60a994 2026-05-25
FileHash-SHA1 1e982096ec2cbe8d2f2a325b59d0a1783f15a994 2026-05-25
FileHash-SHA1 25c14e19526be586b75b52cae8bdb1553c746642 2026-05-25
FileHash-SHA1 3b2926400541e017a043926ebf92dd91ee80d797 2026-05-25
FileHash-SHA1 491ac43610a46ad3a9ca647e6e7b29e6387b2169 2026-05-25
FileHash-SHA1 4b35cda868585a0e593f6d316b17633b1fd42f1c 2026-05-25
FileHash-SHA1 510668d94c3638749b6c945246922679d4db4df7 2026-05-25
FileHash-SHA1 67f41dc48bfd0c0597295259bd3c0d3c09dfea34 2026-05-25
FileHash-SHA1 6e12c54d1861a455c0008ed9ce166e843298a4a0 2026-05-25
FileHash-SHA1 94a0fcc1fb22c6a96abfefbb75bc40afb126f69a 2026-05-25
FileHash-SHA1 a067d4a121af6922fd695e76fa5720135ed12e7b 2026-05-25
FileHash-SHA1 b4538d26e69b64e8160d3577c04b7db8aee6bff4 2026-05-25
FileHash-SHA1 be3b4a74f3872008c4cde0cbe8624e2c15618eaf 2026-05-25
FileHash-SHA1 d64634926ed100d4d8b845df21a69536291afc36 2026-05-25
FileHash-SHA1 da11679653ef33952c3dc8d8850e43d7b8ac884a 2026-05-25
FileHash-SHA1 e508d429e7ded70726f3bfb4e64a26274cebab61 2026-05-25
FileHash-SHA1 f2049d64631264ed6c8ccabdd486763341e18163 2026-05-25
FileHash-SHA1 f687b606e7bdd7533e327c98fecb71937564dc92 2026-05-25
FileHash-SHA1 fca243db4f4671e6425c7813b24585c22137224f 2026-05-25