Screening Serpens (UNC1549) 2026 Espionage Campaign — Six New RATs (MiniUpdate & MiniJunk V2) via AppDomainManager Hijacking

Screening Serpens (UNC1549) 2026 Espionage Campaign (TL-2026-0562), also tracked as Operation Iranian Dream Job 2026, is a high-severity advanced persistent threat campaign, first published 2026-05-22. It is attributed to Screening Serpens (Iran) with high confidence, affects Microsoft .NET Framework, maps to 29 MITRE ATT&CK techniques (T1027, T1027.001, T1036.005), and is covered by 9 detection rules and 54 indicators of compromise.

Key facts for TL-2026-0562

Threat ID
TL-2026-0562
Also known as
Operation Iranian Dream Job 2026, Screening Serpens 2026 Espionage Campaign
Severity
HIGH
Status
ACTIVE
Category
APT
First published
2026-05-22
Last reviewed
2026-05-22
Attribution
Screening Serpens
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
aerospace, defense, telecommunications, technology, video-conferencing, healthcare, financial-services
Target regions
North America, Middle East, Europe, United States, Israel, United Arab Emirates
Detection rules
9
Indicators of compromise
54

Malware and tooling in Screening Serpens (UNC1549) 2026 Espionage Campaign

Malware and tooling: MiniJunk, MiniUpdate

Iran-nexus APT Screening Serpens (UNC1549 / Smoke Sandstorm / Iranian Dream Job / Nimbus Manticore) ran a February-to-April 2026 espionage campaign aligned with the Middle East regional conflict that began Feb 28, 2026, targeting aerospace, defense, telecom and technology professionals across the United States, Israel, the United Arab Emirates, and at least two additional Middle Eastern entities. Unit 42 documented six new RAT variants split across two malware families — MiniUpdate (UpdateChecker.dll) and MiniJunk V2 (unbcl.dll) — delivered via recruitment-themed spear-phishing archives (Hiring Portal.zip, Portable Platform.zip) and executed via DLL sideloading on legitimate signed binaries. The critical TTP evolution is AppDomainManager hijacking: the operators abuse .NET CLR initialization via XML .config directives (etwEnable=false, bypassTrustedAppStrongNames=true, publisherPolicy=no, probing privatePath) to disable EDR telemetry and force local DLL sideloading before the host application's main() function ever executes.

How Screening Serpens (UNC1549) 2026 Espionage Campaign works

Screening Serpens (tracked by Mandiant/Google TIG as UNC1549, Microsoft as Smoke Sandstorm, ClearSky as Iranian Dream Job, and Check Point as Nimbus Manticore) is an Iran-nexus espionage cluster active since at least 2022 with strong overlaps with Iranian Revolutionary Guard Corps (IRGC) intelligence requirements. The 2026 campaign documented by Palo Alto Networks Unit 42 (published 2026-05-22) covers mid-February through mid-April 2026 and overlaps in time with the Middle East regional conflict that began on Feb 28, 2026. Across this window Unit 42 identified six new RAT variants split between two distinct malware families: four MiniUpdate variants (US, Israel, UAE, and a second Middle East target) and two MiniJunk V2 variants (a Middle East target and a US target). All campaigns followed the actor's signature "Iranian Dream Job" social-engineering playbook — spoofed recruitment portals impersonating global air carriers, video-conferencing vendors, and legitimate employment websites, with tailored fake job-requisition PDFs (e.g. "Senior Software Engineer Job ID JR205894.pdf") used as decoys while a parallel sideloading chain executes in the background.

The MiniUpdate family ships as a multi-stage .NET loader chain. Stage 1 — InitInstall.dll — is triggered before the host setup.exe's main() runs by way of an AppDomainManager hijack defined in setup.exe.config. InitInstall.dll decrypts an embedded payload using reverse-byte + ROT13, displays a borderless transparent spinner window to mask background activity, drops the payload under %LOCALAPPDATA%\bin\update (renaming setup.exe→update.exe, UpdateConfig.xml→update.exe.config, and copying Updater.dll plus UpdateChecker.dll), and creates a Task Scheduler entry ("WindowsSecurityUpdate") that fires daily at 09:30 local time. Stage 2 — Updater.dll, again loaded via a second AppDomainManager hijack from update.exe.config — performs anti-analysis: it confirms the current process name is update.exe and that its parent is svchost.exe (i.e. that it was launched by Task Scheduler), silently terminating in any sandbox or interactive context. It then resolves the path to UpdateChecker.dll and invokes the CheckForUpdates export. Stage 3 — UpdateChecker.dll — is the actual MiniUpdate RAT. It polls the C2 over HTTPS GET to /agent/poll, processes a 16-opcode (18 in the April variants) command dispatcher with base64-encoded binary commands, and was observed signed with code-signing certificates impersonated from legitimate software vendors. MiniUpdate operators rotate three to five Azure-hosted domains per target (e.g. buisness-centeral.azurewebsites[.]net for US/Israel, PremierHealthAdvisory[.]com / PremierHealthAdvisory.azurewebsites[.]net for the UAE health-sector target, Ramiltonsfinance[.]com / Ramiltonsfinance.azurewebsites[.]net for the Middle East finance-sector target).

MiniJunk V2 is the evolved iteration of the MiniJunk family previously documented by Check Point Research in late 2025. The initial archive (Portable Platform.zip, March 2026 US campaign) bundles a legitimate Microsoft Setup.exe with three hidden files; the hidden uevmonitor.dll is sideloaded into Setup.exe and drops a renamed legitimate Microsoft binary SoftwareLicencing.exe alongside the malicious unbcl.dll into AppData, then registers a "Synchronize OS" scheduled task for persistence and displays a decoy "Meeting Room URL" prompt to justify the foreground process to the victim. SoftwareLicencing.exe sideloads unbcl.dll — a heavily obfuscated RAT padded with junk code (the family's namesake) and using mixed-bit-arithmetic / XOR string protection. The RAT decrypts five Azure-hosted C2 domains (licencemanagers.azurewebsites[.]net, LicenceSupporting.azurewebsites[.]net, PeerDistSvcManagers.azurewebsites[.]net, ThemesManagers.azurewebsites[.]net, ThemesProviderManagers.azurewebsites[.]net — all mimicking Windows service names), spoofs Microsoft Edge in its User-Agent, and communicates via three API endpoints: /api/app/check (beacon), /api/app/update (command pull), /api/app/comment (exfiltration). The US MiniJunk V2 variant includes Connection.dll with a hardcoded activation gate that no-ops the implant until after 2026-03-27 13:30:00 UTC — a deliberate sandbox-evasion timer matching the deployment window.

The critical TTP evolution across both families is the AppDomainManager hijack delivered through XML .config files. Four directives are weaponised together: <etwEnable enabled="false"/> blinds Event Tracing for Windows, the primary EDR telemetry source for managed-code execution; <bypassTrustedAppStrongNames enabled="true"/> disables strong-name signature verification so the tampered InitInstall.dll/uevmonitor.dll loads silently into a signed host process; <publisherPolicy apply="no"/> prevents the CLR from redirecting to patched assembly versions; <requiredRuntime safemode="true" imageVersion="v4.0.30319"/> pins the runtime to a known version for reliability; and <probing privatePath="./"/> forces local-directory DLL resolution to guarantee the sideload. The CLR's appDomainManagerType / appDomainManagerAssembly hooks ensure that MyAppDomainManager (the actor's custom AppDomainManager type) loads and runs first — before the host application's main() — placing the entire initial-access stage inside an environment where ETW is already disabled. Unit 42 frames this as "execution entirely within a blinded environment."

C2 infrastructure is heavily compartmentalised: 3-5 unique Azure-hosted domains per target/variant, deliberate misspellings of business names (buisness-centeral, recreuitment), sector-themed lookalike domains (health, finance, business central, transportation), and payload staging through legitimate cloud services (ONLYOFFICE DocSpace at docspace-y4cumb.onlyoffice[.]com and docspace-twpf0e.onlyoffice[.]com, and filemail[.]com). User-Agents are tuned per family: Chrome 146.0.0.0 for MiniUpdate and Edge 144.0.0.0 for MiniJunk V2. Attribution to Screening Serpens / UNC1549 is moderate-high confidence based on the identical recruitment-lure playbook, archive naming consistency ("Hiring Portal.zip"), reuse of the AppDomainManager + DLL sideloading chain across both families, junk-code padding consistent with prior MiniJunk samples, sectoral targeting aligned to IRGC priorities (aerospace, defense, telecom), and temporal alignment with the Feb 28 conflict onset.

MITRE ATT&CK techniques used in TL-2026-0562

Defense Evasion

T1027 Obfuscated Files or Information; T1027.001 Binary Padding; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497.001 System Checks; T1497.003 Time Based Checks

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1053.005 Scheduled Task; T1204.002 Malicious File

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1120 Peripheral Device Discovery

Command and Control

T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography

defense-impairment

T1553 Subvert Trust Controls; T1553.002 Code Signing; T1685 Disable or Modify Tools

Initial Access

T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

stealth

T1574.001 DLL; T1574.014 AppDomainManager

Resource Development

T1583 Acquire Infrastructure; T1583.006 Web Services; T1587.001 Malware; T1588.003 Code Signing Certificates

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in Screening Serpens (UNC1549) 2026 Espionage Campaign

  • Microsoft — .NET Framework
    Vulnerable versions: v4.0.30319 and later .NET Framework 4.x
  • Microsoft — Windows (Endpoints with .NET 4.x)
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016+

Remediation for Screening Serpens (UNC1549) 2026 Espionage Campaign

Immediate actions

  • Block all Azure-hosted C2 domains listed in IOCs at proxy/DNS/firewall (buisness-centeral.azurewebsites.net, PremierHealthAdvisory.azurewebsites.net, Ramiltonsfinance.azurewebsites.net, licencemanagers.azurewebsites.net, LicenceSupporting.azurewebsites.net, PeerDistSvcManagers.azurewebsites.net, ThemesManagers.azurewebsites.net, ThemesProviderManagers.azurewebsites.net and their .com lookalikes).
  • Hunt for Task Scheduler entries named 'WindowsSecurityUpdate' (MiniUpdate) and 'Synchronize OS' (MiniJunk V2) across the estate.
  • Hunt for the listed SHA256 hashes on every endpoint and quarantine matches.
  • Hunt for unexpected %LOCALAPPDATA%\bin\update folders containing update.exe, update.exe.config, Updater.dll, UpdateChecker.dll.
  • Hunt for AppData copies of SoftwareLicencing.exe with a co-located unbcl.dll.
  • Block ONLYOFFICE DocSpace download URLs and filemail.com archive downloads at the secure email and web gateway pending review.

Workarounds

  • Disable .NET 4.x AppDomainManager hijacking via Group Policy by enforcing CLR security policies that reject etwEnable=false in application config files.
  • Restrict Task Scheduler task creation to administrators where feasible.
  • Use ASR (Attack Surface Reduction) rule 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion' to slow sideload chains.

Longer-term hardening

  • Deploy EDR rules that alert on any .NET process loading an AppDomainManager declared via .config file (appDomainManagerType / appDomainManagerAssembly).
  • Alert on creation or modification of .exe.config files in user-writable paths, especially with etwEnable=false, bypassTrustedAppStrongNames=true, publisherPolicy apply=no, or probing privatePath=./ directives.
  • Treat legitimate signed binaries (setup.exe, SoftwareLicencing.exe) loading DLLs from %LOCALAPPDATA% or user-writable directories as high-severity behavioural alerts.
  • Implement WDAC / AppLocker policy blocking unsigned DLL loads from user-writable paths.
  • Force CLR strong-name verification estate-wide and audit for bypassTrustedAppStrongNames overrides.
  • Targeted spear-phishing awareness for technology, aerospace, defense, telecom staff covering recruitment-themed lures, spoofed video-conferencing invites, and fake job-requisition PDFs.
  • Egress filtering to Azure App Service (*.azurewebsites.net) with allowlisting of business-required tenants only.

Weaknesses (CWE) in Screening Serpens (UNC1549) 2026 Espionage Campaign

CWE-426, CWE-427, CWE-829

Timeline of Screening Serpens (UNC1549) 2026 Espionage Campaign

  • UNC1549 / Screening Serpens cluster first observed by Mandiant; consistent recruitment-lure tradecraft against aerospace and defense begins.
  • Mandiant publishes 'Suspected Iranian Cyber Espionage Campaign Targets Aerospace, Aviation and Defense', publicly attributing UNC1549 to Iran-nexus operations.
  • Check Point Research documents Nimbus Manticore deploying new malware (original MiniJunk) into Western European targets — actor's strategic expansion beyond the Middle East.
  • First MiniJunk V2 sample (Middle East target) uploaded to VirusTotal — earliest 2026 activity in the Unit 42 dataset.
  • Middle East regional conflict begins; Screening Serpens operational tempo escalates and target mix shifts to align with IRGC collection priorities.
  • MiniUpdate samples uploaded for US and Israel campaigns; US lure impersonates a global air carrier, Israel lure clones a video-conferencing meeting invitation served via filemail.com.
  • Second MiniJunk V2 sample uploaded (US campaign, Portable Platform.zip with 'Meeting Room URL' decoy); Connection.dll variant ships with a hardcoded activation gate dated 2026-03-27 13:30:00 UTC.
  • MiniUpdate variant uploaded targeting UAE entity; C2 staged on PremierHealthAdvisory[.]com and Azure lookalikes to blend into health-sector traffic.
  • MiniUpdate variant uploaded targeting an additional Middle Eastern entity; C2 staged on Ramiltonsfinance[.]com lookalike to blend into financial-sector traffic.
  • Unit 42 publishes 'Tracking Iranian APT Screening Serpens' 2026 Espionage Campaigns', documenting six new RAT variants, the AppDomainManager hijack technique, and full IOC set.
  • As of 2026-05-29, this Iran-nexus UNC1549/Screening Serpens campaign remains a live concern: Unit 42's 2026-05-22 report and Check Point's parallel reporting state activity "shows no signs of slowing down" into April 2026, with no takedown, sinkhole, or arrests. The actor is escalating amid the Feb 2026 conflict, rotating Azure C2 and debuting successor tooling (MiniFast), and the AppDomainManager-hijack TTP stays viable.

Sources cited for Screening Serpens (UNC1549) 2026 Espionage Campaign

Threats related to Screening Serpens (UNC1549) 2026 Espionage Campaign

Detection coverage for TL-2026-0562

As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0562 across Splunk SPL, Microsoft KQL and Sigma, covering 54 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats