CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 600

As cited

Copy frozen at (site build).

threat intel

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict

Nimbus Manticore, an Iranian IRGC-affiliated threat actor, resurfaced during escalated US-Iran military tensions in early 2026 with enhanced capabilities including a new backdoor called MiniFast and novel delivery techniques. The group conducted phishing campaigns targeting aviation and software sector employees across the United States, Europe, and the Middle East, employing methods such as SEO poisoning, AppDomain hijacking, and abuse of legitimate Zoom installers. The malware development appeared to incorporate AI-assisted practices, enabling rapid tool adaptation and sustained operational activity.

Why it matters: Organizations in defense, aviation, and telecommunications sectors in the US, Europe, and Middle East should review phishing controls and monitor for AppDomain hijacking and SEO-poisoned search results, as this threat actor actively targets these industries during geopolitical escalation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict

Nimbus Manticore, an IRGC-affiliated Iranian threat actor, conducted a sustained cyber campaign during the February 2026 US military operation against Iran, targeting aviation and software sector employees across multiple regions with malicious lures. The group employed new techniques including AppDomain hijacking for code execution, SEO poisoning for malware distribution, and introduced a previously undocumented backdoor called MiniFast that incorporates artificial intelligence (AI)-assisted development to accelerate tool creation. The campaign demonstrates the actor's evolution toward more sophisticated and rapidly deployable malware capabilities during active geopolitical conflict.

Why it matters: Defense, aviation, and telecommunications practitioners should treat this as an active threat: the group is actively developing AI-enhanced tools and blending malware delivery into legitimate workflows (Zoom installers), making detection harder and exploitation faster during periods of heightened tension.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict

Nimbus Manticore, an IRGC-affiliated Iranian threat actor, conducted a sustained cyber campaign during the February 2026 US military operation against Iran, targeting aviation and software sector employees across multiple regions with malicious lures. The group employed new techniques including AppDomain hijacking for code execution, SEO poisoning for malware distribution, and introduced a previously undocumented backdoor called MiniFast that incorporates artificial intelligence (AI)-assisted development to accelerate tool creation. The campaign demonstrates the actor's evolution toward more sophisticated and rapidly deployable malware capabilities during active geopolitical conflict.

Why it matters: Defense, aviation, and telecommunications practitioners should treat this as an active threat: the group is actively developing AI-enhanced tools and blending malware delivery into legitimate workflows (Zoom installers), making detection harder and exploitation faster during periods of heightened tension.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict

Nimbus Manticore, an IRGC-affiliated Iranian threat actor, conducted a sustained cyber campaign during the February 2026 US military operation against Iran, targeting aviation and software sector employees across multiple regions with malicious lures. The group employed new techniques including AppDomain hijacking for code execution, SEO poisoning for malware distribution, and introduced a previously undocumented backdoor called MiniFast that incorporates artificial intelligence (AI)-assisted development to accelerate tool creation. The campaign demonstrates the actor's evolution toward more sophisticated and rapidly deployable malware capabilities during active geopolitical conflict.

Why it matters: Defense, aviation, and telecommunications practitioners should treat this as an active threat: the group is actively developing AI-enhanced tools and blending malware delivery into legitimate workflows (Zoom installers), making detection harder and exploitation faster during periods of heightened tension.

VendorsMicrosoftZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary