Nimbus Manticore, an Iranian state-sponsored hacking group, is expanding its operations into Western Europe, cybersecurity experts at Check Point Research have warned. The group is targeting specific companies in the defense, telecommunications, and aviation sectors for espionage purposes.
Nimbus Manticore is a specialized advanced persistent threat (APT) group linked to Iranian intelligence services. Also known as UNC1549 or Smoke Sandstorm, it was previously associated with the “Iranian Dream Job” campaign. Since the beginning of 2025, Check Point Research has observed several waves of its activity. The group is primarily known for its spear-phishing campaigns (targeted email/SMS attacks) designed to trick individuals into installing custom malware implants, including one known as Minibike.
Although Nimbus Manticore has traditionally focused on the Middle East – particularly Israel and the United Arab Emirates – recent operations indicate growing interest in Western Europe, especially Denmark, Sweden, and Portugal. The sectors it targets – telecommunications (particularly satellite providers), defense contractors, aerospace, and airlines – align closely with the strategic priorities of the Islamic Revolutionary Guard Corps (IRGC), which seeks intelligence on sensitive suppliers during heightened geopolitical tensions.
Evolving Malware: From Minibike to MiniJunk
First identified in 2022, Minibike has since evolved to include code obfuscation, modular architecture, and backup command-and-control (C2) infrastructure. Recent activity shows a significant increase in sophistication, including previously unseen DLL side-loading techniques through modified process execution parameters.
The new MiniJunk variant illustrates Nimbus Manticore’s continuous efforts to improve its malware to evade detection. Alongside MiniJunk, the group also uses MiniBrowse, enabling persistent access to victim systems, effective data theft, and stealthy operations.
Fake Recruitment Portals and Spear Phishing
Nimbus Manticore deploys fake recruitment portals and advanced spear-phishing campaigns to lure victims. Malicious files are disguised as part of recruitment processes, with attackers impersonating large local and global companies in the aviation sector.
“We identified a correlation between malware delivery websites and the sectors they target,” Check Point Research noted. For example, a fake recruitment portal mimicking a telecommunications company would specifically target individuals and organizations within that industry.
Growing Threat to Europe
“Over the past year, Nimbus Manticore has expanded its malware arsenal, delivery methods, and attack strategies. By transforming Minibike into MiniJunk, deploying MiniBrowse, and refining spear-phishing campaigns, the group has demonstrated resilience and stealth, even during times of geopolitical conflict,” Check Point experts emphasized.
Researchers warn that the group’s expansion into Europe’s defense, telecommunications, and aviation sectors highlights an intensifying Iranian cyber-espionage campaign aligned with IRGC priorities.
To counter these threats, organizations need protection that blocks attacks before they reach employees. “One effective way to fight such attacks is to deploy spear-phishing detection and prevention systems that intercept malicious campaigns at the email level,” the report concludes.
Source: ManagerPlus.pl





