Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll Implant
Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix (TL-2026-0656), also tracked as Nimbus Manticore Ebix Recruitment Campaign, is a high-severity malware campaign, first published 2026-06-02. It is attributed to UNC1549 (Iran) with high confidence, affects Microsoft Windows (.NET CLR AppDomainManager configuration), maps to 21 MITRE ATT&CK techniques (T1027, T1036.005, T1041), and is covered by 9 detection rules and 38 indicators of compromise.
Key facts for TL-2026-0656
- Threat ID
- TL-2026-0656
- Also known as
- Nimbus Manticore Ebix Recruitment Campaign, TOTPGuard AppDomainManager Chain, 2FAGuard Implant
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-06-02
- Last reviewed
- 2026-06-02
- Attribution
- UNC1549
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- aerospace, defense, aviation, telecommunications
- Target regions
- Middle East, Europe, Africa, North America
- Detection rules
- 9
- Indicators of compromise
- 38
Malware and tooling in Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
Malware and tooling: SSL.com certs: Gray Matter Software S.R.L.; Kirubel Kerie Negeya
IRGC-affiliated APT Nimbus Manticore (UNC1549 / Smoke Sandstorm) ran a LinkedIn recruitment lure impersonating headhunters for a fake 'Ebix' hiring portal (ebix[.]recruitment-flow[.]com), tricking aerospace and defense targets into downloading a fake 2FA app. The package pairs a renamed-legitimate Microsoft binary (ServiceHub.VSDetouredHost.exe renamed to setup.exe) with a malicious setup.exe.config that forces the .NET runtime to load a custom AppDomainManager from TOTPGuard.dll, which AES-decrypts and drops the main.dll native implant beaconing to Azure-hosted (azurewebsites.net) C2. Targets aerospace and defense in the Middle East and Europe.
How Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix works
Nimbus Manticore — tracked by Google/Mandiant as UNC1549 and by Microsoft as Smoke Sandstorm — is an Iran-nexus (IRGC-affiliated) espionage actor that resurfaced during the Iranian conflict (Operation Epic Fury, the US military campaign against Iran launched 2026-02-28). This campaign, documented by Nextron Systems on 2026-06-01 and contextualized by Check Point Research on 2026-05-22, is a material escalation over the actor's earlier SQL Developer SEO-poisoning operation (TL-2026-0581): it introduces a new recruitment-portal initial-access vector and a new TOTPGuard.dll -> main.dll loader/implant pair.
INITIAL ACCESS & SOCIAL ENGINEERING: Operators impersonate recruiters on LinkedIn, dangling high-value (~$200,000 USD) aerospace/defense positions. Victims are steered to a fake Ebix hiring portal at hxxps://ebix[.]recruitment-flow[.]com/ (registered via Namecheap, fronted by Cloudflare). After a fake authentication step, the portal serves a '2FA application' as a ZIP archive (TOTPGuard.zip) containing the malware. Lure PDFs (fake Ebix and fake Airbus job descriptions) carry metadata Author 'Jerry' and Creator 'Microsoft Word LTSC'.
EXECUTION — APPDOMAINMANAGER HIJACKING (T1574.014): The ZIP contains three files: setup.exe (a renamed, validly-signed legitimate Microsoft ServiceHub.VSDetouredHost.exe), TOTPGuard.dll (custom AppDomainManager, hidden attribute), and setup.exe.config (modified, hidden attribute). Rather than classic DLL search-order sideloading, the operators set the .NET probing path to the current directory and add binding directives in the .config that cause the CLR to resolve the attacker-controlled assembly named 'TOTPGuard' as the AppDomainManager for the legitimate signed host — execution flows into attacker code under cover of a trusted, signed Microsoft binary.
STAGER (TOTPGuard.dll): On launch, setup.exe shows a functional fake Ebix 2FA generator UI requesting a 'secret key' (input is irrelevant to execution — pure decoy). In the background the stager AES-decrypts an embedded payload using hardcoded key '1234567890123456' and IV 'abcdefghijklmnop', writes it to %AppData%\Roaming\2FAGuard\main.dll, copies setup.exe and setup.exe.config into the same directory, and creates a scheduled task named 'BackupCheck' that runs 'setup.exe doit' at logon. The stager leaks a PDB/development artifact string 'AppDomainInjection' and campaign constants 'MyCompany-Product-TOTP-Salt-2024!@#$', 'TOTPGuardRunner', and 'DailyTrigger'.
NATIVE IMPLANT (main.dll): A 64-bit Windows PE DLL whose single export 'CheckForUpdates' (resolved by ordinal 1) is the entry point. On the 'doit' code path the stager bypasses the 2FA GUI and LoadLibrary-loads main.dll from %AppData%\Roaming\2FAGuard\. The implant performs environmental guardrails (verifies its module name is setup.exe and that the parent process is NOT svchost.exe), anti-analysis (PEB NtGlobalFlag debugger detection, inline anti-debug, control-flow flattening with dynamically computed indirect jumps, opaque predicates, and heavy junk code), and runtime string protection (the related MiniFast lineage uses ROT13 and reversed-string transforms). It is functionally aligned with the actor's MiniFast/MiniBike backdoor family (17-opcode command set: directory listing, file ops, process enumeration, DLL loading, UAC elevation, persistence installation).
C2: The implant beacons over HTTPS to Azure App Service domains (azurewebsites.net) using JSON-formatted API calls and User-Agent 'Mozilla/5.0 ... Chrome/146.0.0.0 Safari/537.36'. Observed routes: POST /rg (initial handshake), POST /agent/init (victim registration), GET /agent/poll?token= (task retrieval), POST /agent/result (result upload), PUT /upload/ (file exfiltration). C2 domains follow a generic 'IT consultants / business checkers / exam joiners' naming pattern. Domains were registered roughly 10 days before the incident; TLS certificates were issued 2026-04-15. Check Point observed the actor abusing SSL.com certificates issued to 'Gray Matter Software S.R.L.' and 'Kirubel Kerie Negeya' across related infrastructure. Both vendors note strong indications of AI-assisted malware development (excessive error handling, verbose identifiers, modular organization, detailed error strings).
IMPACT: Successful compromise yields persistent, signed-binary-cloaked remote access on aerospace/defense engineering endpoints, enabling espionage-grade collection, file exfiltration, and follow-on tasking against sensitive defense programs in the Middle East and Europe.
MITRE ATT&CK techniques used in TL-2026-0656
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1574.001 DLL; T1574.014 AppDomainManager; T1622 Debugger Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573.001 Symmetric Cryptography
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1583.006 Web Services; T1588.004 Digital Certificates
Reconnaissance
Affected products and versions in Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
- Microsoft — Windows (.NET CLR AppDomainManager configuration)
Vulnerable versions: Windows 10; Windows 11; Windows Server with .NET Framework
Fixed in: N/A — abuse of legitimate .NET feature, not a patchable CVE - Microsoft — ServiceHub.VSDetouredHost.exe (Visual Studio component, abused as signed host)
Vulnerable versions: legitimate signed binary renamed to setup.exe
Fixed in: N/A
Remediation for Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
Immediate actions
- Block delivery domain ebix[.]recruitment-flow[.]com and all listed *.azurewebsites.net C2 domains at the proxy/DNS layer
- Hunt for scheduled task 'BackupCheck' with argument 'doit' across the fleet
- Hunt for %AppData%\Roaming\2FAGuard\ directory and main.dll on disk
- Block/quarantine the listed SHA256 file hashes via EDR
- Search for renamed ServiceHub.VSDetouredHost.exe (setup.exe) executing with a sibling setup.exe.config from user-writable paths
Workarounds
- Restrict execution of unsigned/renamed .config-paired binaries from user profile directories
- Disable scheduled-task creation by non-admin users via GPO where feasible
Longer-term hardening
- Deploy AppLocker/WDAC policies blocking execution from %TEMP%, %APPDATA%, %LOCALAPPDATA%, and Downloads
- Enable .NET CLR AppDomainManager / config-file abuse telemetry and alert on signed binaries loading non-GAC AppDomainManager assemblies
- Deploy EDR with behavioral detection for AppDomain hijacking and scheduled-task persistence
- Block newly-registered domains (age < 30 days) for HR/recruiting and finance user populations
- Security-awareness training on LinkedIn recruitment lures targeting aerospace/defense staff
Weaknesses (CWE) in Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
CWE-426, CWE-427, CWE-494, CWE-829
Timeline of Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
- Operation Epic Fury (US military campaign against Iran) begins; Nimbus Manticore resurfaces with wartime tempo per Check Point Research.
- TLS certificates for the Azure-hosted C2 domains issued, indicating staging of the recruitment-portal campaign infrastructure.
- Delivery and C2 domains registered roughly 10 days before observed exploitation (newly-registered domains via Namecheap, fronted by Cloudflare).
- Check Point Research publishes 'Fast and Furious — Nimbus Manticore Operations During the Iranian Conflict' documenting actor TTPs, AppDomain hijacking, and AI-assisted development.
- Nextron Systems publishes full technical analysis of the fake Ebix recruitment portal -> TOTPGuard.dll AppDomainManager -> main.dll chain with complete IOC and YARA set.
- Threadlinqs Intelligence publishes TL-2026-0656 with MITRE mapping, IOCs, and detection coverage for SOC/IR consumption.
Sources cited for Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
- Detecting Nimbus Manticore and their sideloading infection chains
- Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict
- MITRE ATT&CK T1574.014 — Hijack Execution Flow: AppDomainManager
- MITRE ATT&CK T1573.001 — Encrypted Channel: Symmetric Encryption
- MITRE ATT&CK T1053.005 — Scheduled Task
- Related campaign: UNC1549 SQL Developer SEO-poisoning / MiniFast (TL-2026-0581)
Threats related to Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix
Detection coverage for TL-2026-0656
As of 2026-06-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0656 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.