Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll Implant

Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix (TL-2026-0656), also tracked as Nimbus Manticore Ebix Recruitment Campaign, is a high-severity malware campaign, first published 2026-06-02. It is attributed to UNC1549 (Iran) with high confidence, affects Microsoft Windows (.NET CLR AppDomainManager configuration), maps to 21 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 38 indicators of compromise.

Key facts for TL-2026-0656

Threat ID
TL-2026-0656
Also known as
Nimbus Manticore Ebix Recruitment Campaign, TOTPGuard AppDomainManager Chain, 2FAGuard Implant
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-06-02
Last reviewed
2026-06-02
Attribution
UNC1549
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
aerospace, defense, aviation, telecommunications
Target regions
Middle East, Europe, Africa, North America
Detection rules
9
Indicators of compromise
38

Malware and tooling in Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

Malware and tooling: SSL.com certs: Gray Matter Software S.R.L.; Kirubel Kerie Negeya

IRGC-affiliated APT Nimbus Manticore (UNC1549 / Smoke Sandstorm) ran a LinkedIn recruitment lure impersonating headhunters for a fake 'Ebix' hiring portal (ebix[.]recruitment-flow[.]com), tricking aerospace and defense targets into downloading a fake 2FA app. The package pairs a renamed-legitimate Microsoft binary (ServiceHub.VSDetouredHost.exe renamed to setup.exe) with a malicious setup.exe.config that forces the .NET runtime to load a custom AppDomainManager from TOTPGuard.dll, which AES-decrypts and drops the main.dll native implant beaconing to Azure-hosted (azurewebsites.net) C2. Targets aerospace and defense in the Middle East and Europe.

How Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix works

Nimbus Manticore — tracked by Google/Mandiant as UNC1549 and by Microsoft as Smoke Sandstorm — is an Iran-nexus (IRGC-affiliated) espionage actor that resurfaced during the Iranian conflict (Operation Epic Fury, the US military campaign against Iran launched 2026-02-28). This campaign, documented by Nextron Systems on 2026-06-01 and contextualized by Check Point Research on 2026-05-22, is a material escalation over the actor's earlier SQL Developer SEO-poisoning operation (TL-2026-0581): it introduces a new recruitment-portal initial-access vector and a new TOTPGuard.dll -> main.dll loader/implant pair.

INITIAL ACCESS & SOCIAL ENGINEERING: Operators impersonate recruiters on LinkedIn, dangling high-value (~$200,000 USD) aerospace/defense positions. Victims are steered to a fake Ebix hiring portal at hxxps://ebix[.]recruitment-flow[.]com/ (registered via Namecheap, fronted by Cloudflare). After a fake authentication step, the portal serves a '2FA application' as a ZIP archive (TOTPGuard.zip) containing the malware. Lure PDFs (fake Ebix and fake Airbus job descriptions) carry metadata Author 'Jerry' and Creator 'Microsoft Word LTSC'.

EXECUTION — APPDOMAINMANAGER HIJACKING (T1574.014): The ZIP contains three files: setup.exe (a renamed, validly-signed legitimate Microsoft ServiceHub.VSDetouredHost.exe), TOTPGuard.dll (custom AppDomainManager, hidden attribute), and setup.exe.config (modified, hidden attribute). Rather than classic DLL search-order sideloading, the operators set the .NET probing path to the current directory and add binding directives in the .config that cause the CLR to resolve the attacker-controlled assembly named 'TOTPGuard' as the AppDomainManager for the legitimate signed host — execution flows into attacker code under cover of a trusted, signed Microsoft binary.

STAGER (TOTPGuard.dll): On launch, setup.exe shows a functional fake Ebix 2FA generator UI requesting a 'secret key' (input is irrelevant to execution — pure decoy). In the background the stager AES-decrypts an embedded payload using hardcoded key '1234567890123456' and IV 'abcdefghijklmnop', writes it to %AppData%\Roaming\2FAGuard\main.dll, copies setup.exe and setup.exe.config into the same directory, and creates a scheduled task named 'BackupCheck' that runs 'setup.exe doit' at logon. The stager leaks a PDB/development artifact string 'AppDomainInjection' and campaign constants 'MyCompany-Product-TOTP-Salt-2024!@#$', 'TOTPGuardRunner', and 'DailyTrigger'.

NATIVE IMPLANT (main.dll): A 64-bit Windows PE DLL whose single export 'CheckForUpdates' (resolved by ordinal 1) is the entry point. On the 'doit' code path the stager bypasses the 2FA GUI and LoadLibrary-loads main.dll from %AppData%\Roaming\2FAGuard\. The implant performs environmental guardrails (verifies its module name is setup.exe and that the parent process is NOT svchost.exe), anti-analysis (PEB NtGlobalFlag debugger detection, inline anti-debug, control-flow flattening with dynamically computed indirect jumps, opaque predicates, and heavy junk code), and runtime string protection (the related MiniFast lineage uses ROT13 and reversed-string transforms). It is functionally aligned with the actor's MiniFast/MiniBike backdoor family (17-opcode command set: directory listing, file ops, process enumeration, DLL loading, UAC elevation, persistence installation).

C2: The implant beacons over HTTPS to Azure App Service domains (azurewebsites.net) using JSON-formatted API calls and User-Agent 'Mozilla/5.0 ... Chrome/146.0.0.0 Safari/537.36'. Observed routes: POST /rg (initial handshake), POST /agent/init (victim registration), GET /agent/poll?token= (task retrieval), POST /agent/result (result upload), PUT /upload/ (file exfiltration). C2 domains follow a generic 'IT consultants / business checkers / exam joiners' naming pattern. Domains were registered roughly 10 days before the incident; TLS certificates were issued 2026-04-15. Check Point observed the actor abusing SSL.com certificates issued to 'Gray Matter Software S.R.L.' and 'Kirubel Kerie Negeya' across related infrastructure. Both vendors note strong indications of AI-assisted malware development (excessive error handling, verbose identifiers, modular organization, detailed error strings).

IMPACT: Successful compromise yields persistent, signed-binary-cloaked remote access on aerospace/defense engineering endpoints, enabling espionage-grade collection, file exfiltration, and follow-on tasking against sensitive defense programs in the Middle East and Europe.

MITRE ATT&CK techniques used in TL-2026-0656

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL; T1574.014 AppDomainManager; T1622 Debugger Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053.005 Scheduled Task

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography

Execution

T1204.001 Malicious Link; T1204.002 Malicious File

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583 Acquire Infrastructure; T1583.006 Web Services; T1588.004 Digital Certificates

Reconnaissance

T1598 Phishing for Information

Affected products and versions in Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

  • Microsoft — Windows (.NET CLR AppDomainManager configuration)
    Vulnerable versions: Windows 10; Windows 11; Windows Server with .NET Framework
    Fixed in: N/A — abuse of legitimate .NET feature, not a patchable CVE
  • Microsoft — ServiceHub.VSDetouredHost.exe (Visual Studio component, abused as signed host)
    Vulnerable versions: legitimate signed binary renamed to setup.exe
    Fixed in: N/A

Remediation for Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

Immediate actions

  • Block delivery domain ebix[.]recruitment-flow[.]com and all listed *.azurewebsites.net C2 domains at the proxy/DNS layer
  • Hunt for scheduled task 'BackupCheck' with argument 'doit' across the fleet
  • Hunt for %AppData%\Roaming\2FAGuard\ directory and main.dll on disk
  • Block/quarantine the listed SHA256 file hashes via EDR
  • Search for renamed ServiceHub.VSDetouredHost.exe (setup.exe) executing with a sibling setup.exe.config from user-writable paths

Workarounds

  • Restrict execution of unsigned/renamed .config-paired binaries from user profile directories
  • Disable scheduled-task creation by non-admin users via GPO where feasible

Longer-term hardening

  • Deploy AppLocker/WDAC policies blocking execution from %TEMP%, %APPDATA%, %LOCALAPPDATA%, and Downloads
  • Enable .NET CLR AppDomainManager / config-file abuse telemetry and alert on signed binaries loading non-GAC AppDomainManager assemblies
  • Deploy EDR with behavioral detection for AppDomain hijacking and scheduled-task persistence
  • Block newly-registered domains (age < 30 days) for HR/recruiting and finance user populations
  • Security-awareness training on LinkedIn recruitment lures targeting aerospace/defense staff

Weaknesses (CWE) in Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

CWE-426, CWE-427, CWE-494, CWE-829

Timeline of Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

  • Operation Epic Fury (US military campaign against Iran) begins; Nimbus Manticore resurfaces with wartime tempo per Check Point Research.
  • TLS certificates for the Azure-hosted C2 domains issued, indicating staging of the recruitment-portal campaign infrastructure.
  • Delivery and C2 domains registered roughly 10 days before observed exploitation (newly-registered domains via Namecheap, fronted by Cloudflare).
  • Check Point Research publishes 'Fast and Furious — Nimbus Manticore Operations During the Iranian Conflict' documenting actor TTPs, AppDomain hijacking, and AI-assisted development.
  • Nextron Systems publishes full technical analysis of the fake Ebix recruitment portal -> TOTPGuard.dll AppDomainManager -> main.dll chain with complete IOC and YARA set.
  • Threadlinqs Intelligence publishes TL-2026-0656 with MITRE mapping, IOCs, and detection coverage for SOC/IR consumption.

Sources cited for Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

Threats related to Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix

Detection coverage for TL-2026-0656

As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0656 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats