Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via AppDomainManager Hijacking — Threadlinqs Intelligence
As of 2026-05-30, Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via AppDomainManager Hijacking is a high-severity apt threat attributed to Screening Serpens (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 54 indicators of compromise.
Threat ID: TL-2026-0562 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Screening Serpens · Iran · ESPIONAGE
Iran-nexus APT Screening Serpens (UNC1549 / Smoke Sandstorm / Iranian Dream Job / Nimbus Manticore) ran a February-to-April 2026 espionage campaign aligned with the Middle East regional conflict that
Screening Serpens (tracked by Mandiant/Google TIG as UNC1549, Microsoft as Smoke Sandstorm, ClearSky as Iranian Dream Job, and Check Point as Nimbus Manticore) is an Iran-nexus espionage cluster active since at least 2022 with strong overlaps with Iranian Revolutionary Guard Corps (IRGC) intelligence requirements. The 2026 campaign documented by Palo Alto Networks Unit 42 (published 2026-05-22) covers mid-February through mid-April 2026 and overlaps in time with the Middle East regional conflict that began on Feb 28, 2026. Across this window Unit 42 identified six new RAT variants split between two distinct malware families: four MiniUpdate variants (US, Israel, UAE, and a second Middle East target) and two MiniJunk V2 variants (a Middle East target and a US target). All campaigns followed the actor's signature "Iranian Dream Job" social-engineering playbook — spoofed recruitment portals impersonating global air carriers, video-conferencing vendors, and legitimate employment websites, with tailored fake job-requisition PDFs (e.g. "Senior Software Engineer Job ID JR205894.pdf") used as decoys while a parallel sideloading chain executes in the background.
The MiniUpdate family ships as a multi-stage .NET loader chain. Stage 1 — InitInstall.dll — is triggered before the host setup.exe's main() runs by way of an AppDomainManager hijack defined in setup.exe.config. InitInstall.dll decrypts an embedded payload using reverse-byte + ROT13, displays a borderless transparent spinner window to mask background activity, drops the payload under %LOCALAPPDATA%\bin\update (renaming setup.exe→update.exe, UpdateConfig.xml→update.exe.config, and copying Updater.dll plus UpdateChecker.dll), and creates a Task Scheduler entry ("WindowsSecurityUpdate") that fires daily at 09:30 local time. Stage 2 — Updater.dll, again loaded via a second AppDomainManager hijack from update.exe.config — performs anti-analysis: it confirms the current process name is update.exe and that its parent is svchost.exe (i.e. that it was launched by Task Scheduler), silently terminating in any sandbox or interactive context. It then resolves the path to UpdateChecker.dll and invokes the CheckForUpdates export. Stage 3 — UpdateChecker.dll — is the actual MiniUpdate RAT. It polls the C2 over HTTPS GET to /agent/poll, processes a 16-opcode (18 in the April variants) command dispatcher with base64-encoded binary commands, and was observed signed with code-signing certificates impersonated from legitimate software vendors. MiniUpdate operators rotate three to five Azure-hosted domains per target (e.g. buisness-centeral.azurewebsites[.]net for US/Israel, PremierHealthAdvisory[.]com / PremierHealthAdvisory.azurewebsites[.]net for the UAE health-sector target, Ramiltonsfinance[.]com / Ramiltonsfinance.azurewebsites[.]net for the Middle East finance-sector target).
MiniJunk V2 is the evolved iteration of the MiniJunk family previously documented by Check Point Research in late 2025. The initial archive (Portable Platform.zip, March 2026 US campaign) bundles a legitimate Microsoft Setup.exe with three hidden files; the hidden uevmonitor.dll is sideloaded into Setup.exe and drops a renamed legitimate Microsoft binary SoftwareLicencing.exe alongside the malicious unbcl.dll into AppData, then registers a "Synchronize OS" scheduled task for persistence and displays a decoy "Meeting Room URL" prompt to justify the foreground process to the victim. SoftwareLicencing.exe sideloads unbcl.dll — a heavily obfuscated RAT padded with junk code (the family's namesake) and using mixed-bit-arithmetic / XOR string protection. The RAT decrypts five Azure-hosted C2 domains (licencemanagers.azurewebsites[.]net, LicenceSupporting.azurewebsites[.]net, PeerDistSvcManagers.azurewebsites[.]net, ThemesManagers.azurewebsites[.]net, ThemesProviderManagers.azurewebsites[.]net — all mimicking Windows service names), spoofs Microsoft Edge in its User-Agent, and communicates via three API endpoints: /api/app/che
Weaknesses (CWE)
CWE-426, CWE-427, CWE-829
Target sectors: aerospace, defense, telecommunications, technology, video-conferencing, healthcare, financial-services
Target regions: North America, Middle East, Europe, United States, Israel, United Arab Emirates
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 54 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1583.006, T1587.001, T1588.003, T1566.001, T1566.002, T1204.002, T1053.005, T1053.005