Nimbus Manticore Deploys New Malware Targeting Europe
The Iranian threat actor Nimbus Manticore has expanded its operations, targeting defense, telecommunications, and aviation sectors in Western Europe. The group uses sophisticated spear-phishing techniques, impersonating HR recruiters to lure victims to fake career portals. Their toolset includes the MiniJunk backdoor and MiniBrowse stealer, which have evolved to employ advanced evasion techniques like multi-stage DLL sideloading, heavy obfuscation, and code signing. The malware infrastructure leverages Azure App Services for resilient command and control. Nimbus Manticore's recent activities demonstrate increased focus on stealth, operational security, and expanding their targeting to align with Iranian strategic priorities.
Pulse ID: 68d1c1ecdb0b4acf0cc29af1
Pulse Link: https://otx.alienvault.com/pulse/68d1c1ecdb0b4acf0cc29af1
Pulse Author: AlienVault
Created: 2025-09-22 21:38:52
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Azure #BackDoor #CyberSecurity #Europe #InfoSec #Iran #Malware #Nim #OTX #OpenThreatExchange #Phishing #RAT #SideLoading #SpearPhishing #Telecom #Telecommunication #WesternEurope #bot #AlienVault