Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning Campaign Delivers MiniFast Backdoor via AppDomain Hijacking — Operation Epic Fury Wave 3
Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning (TL-2026-0581), also tracked as Operation Epic Fury Wave 3, is a high-severity malware campaign, first published 2026-05-25. It is attributed to UNC1549 (Iran) with high confidence, affects Oracle SQL Developer (impersonated brand), maps to 34 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 64 indicators of compromise.
Key facts for TL-2026-0581
- Threat ID
- TL-2026-0581
- Also known as
- Operation Epic Fury Wave 3, SQL Developer Campaign, MiniFast Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-05-25
- Last reviewed
- 2026-05-25
- Attribution
- UNC1549
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- aviation, aerospace, defense, telecommunications, software-development, critical-infrastructure
- Target regions
- Europe, Middle East, Israel, United Arab Emirates, Africa, North America
- Detection rules
- 9
- Indicators of compromise
- 64
Malware and tooling in Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
Malware and tooling: MiniFast
Iranian APT Nimbus Manticore (UNC1549, IRGC-affiliated) executed the 'SQL Developer' campaign in April 2026, the third and final wave of Operation Epic Fury (February–April 2026). The actor registered getsqldeveloper[.]com and dozens of supporting domains to impersonate Oracle SQL Developer, leveraging SEO poisoning to surface near the top of Bing and DuckDuckGo results for 'sql developer'. The weaponized installer deploys MiniFast, a new 64-bit Windows DLL backdoor, by abusing .NET AppDomain Hijacking — a trojanized .config file routes the legitimate Microsoft-signed Setup.exe (ServiceHub.VSDetouredHost.exe) into loading the attacker-controlled DLL inside a trusted process context.
How Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning works
On 22 May 2026 Check Point Research published 'Fast and Furious — Nimbus Manticore Operations During the Iranian Conflict', documenting three Nimbus Manticore (UNC1549) campaign waves that ran February–April 2026, coinciding with the US/Israel-Iran military confrontation. The third wave, tracked here as TL-2026-0581, represents a significant TTP shift away from the group's traditional fake-job-offer spearphishing toward opportunistic SEO poisoning of software search queries.
INITIAL ACCESS — SEO POISONING. The actor stood up getsqldeveloper[.]com as a near-pixel-perfect clone of Oracle's SQL Developer download page. Reputation was manufactured by dozens of linking 'doorway' domains (azurewebsites.net subdomains, business-startup[.]org, ramiltonsfinance[.]com, PremierHealthAdvisory[.]com, nanomatrix.azurewebsites[.]net, globalitconsultants.azurewebsites[.]net, peerdistsvcmanagers.azurewebsites[.]net, etc.) plus aggressive keyword stuffing of 'Download SQL Developer'. The site achieved top placement on Bing and DuckDuckGo for 'sql developer' queries. Victims downloading the binary received a ZIP archive structured identically to the Wave 2 Zoom-themed package: a benign Microsoft-signed Setup.exe (ServiceHub.VSDetouredHost.exe), Setup.exe.config (the AppDomain Hijacking config), a first-stage loader DLL (InitInstall.dll), UpdateConfig.xml (a second AppDomain config), Updater.dll (second-stage loader), and UpdateChecker.dll (the MiniFast payload, exposed via the CheckForUpdates export).
EXECUTION — APPDOMAIN HIJACKING. When the victim runs Setup.exe, the .NET runtime parses the colocated Setup.exe.config file, which specifies an attacker-controlled AppDomainManager assembly (InitInstall.dll). The runtime resolves and loads the malicious DLL inside the trusted Microsoft-signed binary's process. InitInstall.dll first validates its host is Setup.exe, displays a decoy error ('Couldn't connect to survey server'), and then drops the stage-2 payload tree into C:\Users\<USER>\AppData\Local\Zoom\bin\update\ (the Wave-3 SQL Developer variant reuses Wave-2's Zoom-themed AppData layout). A second AppDomain Hijack — driven by UpdateConfig.xml against the renamed Update.exe — loads Updater.dll, which side-loads UpdateChecker.dll and invokes its CheckForUpdates export. Updater.dll validates its host process is update.exe with parent svchost.exe before continuing. Both loader DLLs employ runtime string decryption combining ROT13 with reversed-string transformations.
PERSISTENCE. Instead of creating new scheduled tasks, MiniFast hijacks legitimate Zoom auto-update tasks (ZoomUpdateTaskUser-<SID>) by rewriting their action target — blending with expected user-mode scheduled tasks. The optional MiniFast persistence opcode 0xB1 installs a fresh scheduled task named 'WindowsSecurityUpdate' pointed at the MiniFast binary path.
C2 PROTOCOL — MINIFAST. MiniFast is a 64-bit Windows PE DLL backdoor designed as a long-stay RAT, replacing the prior MiniJunk/MiniUpdate families documented in TL-2026-0562. It communicates over HTTP with a hardcoded Chrome User-Agent: 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36'. The endpoint map is structured: POST /rg performs the initial handshake (the server responds HTTP 400 with a JSON body containing socketId, pollInterval defaulting to 120000 ms, and jitterTime of 5000 ms); POST /agent/init registers the victim with computer name, user name, domain, and elevation state; GET /agent/poll?token= retrieves base64-wrapped task structures; POST /agent/result returns base64-encoded result envelopes (taskIdLen, taskId, status uint32, resultText); PUT /upload/ exfiltrates files; GET /files/ pulls operator-pushed payloads.
COMMAND SET. Tasks are dispatched by single-byte opcode: 0x02 list directory, 0x03 move/rename, 0x04 execute shell (cmd.exe /c), 0x05 enumerate processes, 0x06 delete, 0x07 download from C2, 0x08 upload to C2, 0x09 enumerate drives, 0x0A kill process, 0x0B load arbitrary DLL by path+export, 0x0C create directory, 0x0D create ZIP archive (built-in stager), 0xB0 request UAC elevation via runas, 0xB1 install persistence scheduled task 'WindowsSecurityUpdate', 0xF0 retune poll interval, 0xF1 idle acknowledge, 0xF2 retune jitter.
CODE-SIGNING ABUSE. Loaders observed in this wave carry valid Authenticode signatures issued through SSL.com under shell company names 'Gray Matter Software S.R.L.' and 'Kirubel Kerie Negeya' — a continuation of UNC1549's pattern of standing up disposable code-signing identities.
AI-ASSISTED DEVELOPMENT SIGNATURE. Check Point assesses with medium-to-high confidence that components of MiniFast and the loaders were generated with LLM assistance: excessive defensive error handling around trivial Win32 calls (e.g., wrapping GetUserName), unusually verbose function naming, modular over-engineering of small routines, and large embedded debug strings.
TARGETING. Confirmed sector verticals: aviation, software development, defense, and telecommunications. Confirmed regions: Europe, Middle East (Israel and UAE heavily represented), Africa, with expansion into US aviation targets during Wave 3. The SQL Developer lure is opportunistic — anyone searching for the Oracle tool is potentially in-scope, broadening the victim aperture beyond UNC1549's prior career-themed phishing victims.
ATTRIBUTION. Check Point attributes Nimbus Manticore to Iran's Islamic Revolutionary Guard Corps (IRGC) with high confidence based on TTP overlap with prior UNC1549 / Smoke Sandstorm tracking, infrastructure pivot patterns, timing alignment with Iranian state strategic interests, and persistence under wartime operational pressure. Distinct from but operationally adjacent to TL-2026-0562, which documented the AppDomainManager / MiniUpdate / MiniJunk V2 tradecraft in the same group's prior waves.
MITRE ATT&CK techniques used in TL-2026-0581
Collection
T1005 Data from Local System; T1560.002 Archive Collected Data: Archive via Library
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerading: Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1574.001 DLL; T1574.014 Hijack Execution Flow: AppDomainManager
Discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1120 Peripheral Device Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1546.014 Emond
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1129 Shared Modules
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.002 Web Service: Bidirectional Communication; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1132.002 Non-Standard Encoding
Initial Access
execution
T1204.002 User Execution: Malicious File
Privilege Escalation
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1587.001 Develop Capabilities: Malware; T1588.003 Obtain Capabilities: Code Signing Certificates; T1608.004 Stage Capabilities: Drive-by Target; T1608.006 Stage Capabilities: SEO Poisoning
Affected products and versions in Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
- Oracle — SQL Developer (impersonated brand)
Vulnerable versions: N/A — brand impersonation, no Oracle product is vulnerable - Microsoft — .NET Framework / .NET runtime (AppDomainManager loading abused)
Vulnerable versions: All currently supported versions where AppDomainManager configuration is honored
Remediation for Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
Patches
- No vendor patch — this is malware, not a software vulnerability. Apply defensive controls listed above.
Immediate actions
- Block all Indicator of Compromise domains (getsqldeveloper[.]com, business-startup[.]org, ramiltonsfinance[.]com, PremierHealthAdvisory[.]com, and the documented azurewebsites.net subdomains) at perimeter DNS and web proxy.
- Hash-block all 27 MiniFast / loader SHA256 IOCs in EDR and email gateways.
- Hunt for files created under C:\Users\<USER>\AppData\Local\Zoom\bin\update\ on hosts that did not legitimately install Zoom.
- Audit scheduled tasks named ZoomUpdateTaskUser-* whose action target is not the official Zoom update binary; audit any task named 'WindowsSecurityUpdate'.
- Revoke trust on code-signing certificates issued via SSL.com to 'Gray Matter Software S.R.L.' and 'Kirubel Kerie Negeya'.
Workarounds
- For sensitive environments, prefer DNS-level allowlisting for software download sources (oracle.com, microsoft.com, etc.).
- Disable .NET AppDomainManager loading from non-system paths via security policy where feasible.
Longer-term hardening
- Deploy application-control / WDAC policies to restrict execution of unsigned or non-allowlisted DLLs side-loaded into Microsoft-signed binaries.
- Enable Microsoft Defender ASR rule 'Block process creations originating from PSExec and WMI commands' and 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'.
- Instrument outbound HTTP for unusual JSON POST bodies containing 'socketId'/'pollInterval' patterns against newly-registered or low-reputation domains.
- Monitor egress to *.azurewebsites.net subdomains with low organizational baseline traffic.
- Train developer and engineering staff (the lure-target population) to download tooling only from vendor canonical URLs, not search results.
Weaknesses (CWE) in Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
CWE-426, CWE-829, CWE-494, CWE-345
Timeline of Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
- Wave 1 ('Rising Tension') of Operation Epic Fury begins — Nimbus Manticore distributes OnlyOffice-hosted ZIP archives leveraging AppDomain Hijacking via uevmonitor.dll and Interop.TaskScheduler.dll.
- Wave 2 launches a trojanized Zoom installer package (Zoominstall64.zip) using Setup.exe (ServiceHub.VSDetouredHost.exe), InitInstall.dll, Updater.dll, and the new MiniFast backdoor (UpdateChecker.dll). MiniFast replaces the prior MiniJunk/MiniUpdate family.
- Iran-Israel/US active confrontation enters ceasefire phase; Nimbus Manticore operations briefly slow but infrastructure remains live.
- Wave 3 (the 'SQL Developer' campaign) begins. getsqldeveloper[.]com and supporting doorway domains are stood up and SEO-poisoned to surface on Bing and DuckDuckGo for 'sql developer' queries.
- First confirmed victims observed downloading the SQL Developer-themed ZIP archive containing the MiniFast loader chain (Setup.exe, Setup.exe.config, InitInstall.dll, UpdateConfig.xml, Updater.dll, UpdateChecker.dll).
- Campaign expands beyond traditional Israel/UAE focus to include US aviation sector victims, consistent with opportunistic SEO targeting.
- Check Point Research publishes 'Fast and Furious — Nimbus Manticore Operations During the Iranian Conflict' detailing all three campaign waves, MiniFast protocol, and full IOC set.
- Cybersecurity News, CyberPress, and GBHackers reproduce the disclosure, amplifying defender awareness.
- Threadlinqs Intelligence publishes TL-2026-0581 with full MITRE mapping, IOC set, and detection coverage.
- As of 2026-05-29, this IRGC-linked Nimbus Manticore (UNC1549) MiniFast campaign remains a live concern: Check Point only disclosed it 22 May 2026, with no takedown, sinkhole, or actor disruption reported. The actor is highly adaptive, MiniFast/AppDomain-hijack tradecraft has no vendor patch, and Cloudflare/Azure C2 is built for fast rotation.
Sources cited for Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
- Fast and Furious — Nimbus Manticore Operations During the Iranian Conflict
- Iranian APT Uses SEO Poisoning to Deliver Fake SQL Developer Malware Installer
- Hackers Abuse SEO Poisoning To Spread Fake SQL Developer Malware
- Iranian APT Uses SEO Poisoning to Spread Fake SQL Developer Malware
- Nimbus Manticore Deploys New Malware Targeting Europe
- Iranian Threat Actor Nimbus Manticore Expands Campaigns into Europe
- Check Point tracks Nimbus Manticore Iranian APT targeting critical infrastructure
- Mandiant tracks surge in UNC1549 campaigns hitting aerospace and defense
- MITRE ATT&CK T1574.014 — AppDomainManager Hijacking
Threats related to Nimbus Manticore (UNC1549/IRGC) SQL Developer SEO Poisoning
Detection coverage for TL-2026-0581
As of 2026-05-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0581 across Splunk SPL, Microsoft KQL and Sigma, covering 64 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.