惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
MongoDB | Blog
MongoDB | Blog
云风的 BLOG
云风的 BLOG
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
V
Visual Studio Blog
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
IT之家
IT之家
Vercel News
Vercel News
C
Check Point Blog
Google DeepMind News
Google DeepMind News
月光博客
月光博客
D
DataBreaches.Net
酷 壳 – CoolShell
酷 壳 – CoolShell
美团技术团队
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks
Iran’s Nimbus Manticore Used Trojanized Zoom Installers A...
Deeba Ahmed · 2026-05-28 · via Hackread – Cybersecurity News, Data Breaches, AI and More

If you installed Zoom from unofficial sites earlier this year, your device may have been exposed to malware linked to Iran’s Nimbus Manticore hackers.

Check Point Research (CPR) recently exposed a series of cyberattacks carried out by an Iranian group called Nimbus Manticore (also tracked as UNC1549), which is affiliated with the Islamic Revolutionary Guard Corps (IRGC).

Nimbus Manticore has been most active between February and April 2026- a time of major military tension after the launch of Operation Epic Fury on 28 February 2026. Reportedly, the group has expanded its targets beyond Israel and the UAE to hit aviation and software firms in the US.

Fake Job Offers and Zoom Invites

According to CPR’s blog post, in February 2026, the hackers targeted workers in Saudi Arabia and Australia with fake job offers on OnlyOffice. When victims downloaded a ZIP archive, the group used a technique called AppDomain hijacking. By placing a malicious configuration file (Setup.exe.config) with a safe Microsoft binary (Setup.exe), they tricked the system into running a malicious file (uevmonitor.dll) to launch MiniJunk malware.

By March 2026, they switched to fake Zoom meeting invitations containing Zoominstall64.zip. This launched a real Zoom installer (Zoom_cm.exe) to hide the attack, while AppDomain hijacking quietly deployed a new backdoor called MiniFast via InitInstall.dll. The malware even hijacked a real Windows scheduled task (ZoomUpdateTaskUser) to stay hidden on the system.

Attack chain during Operation Epic Fury (Source: Check Point Research)

Search Engine Tricks

MiniFast stands out for showing clear signs of AI-assisted development. The code was exceptionally neat, featured modular organisation, and included excessive error handling for basic tasks such as GetUserName. This allowed the group to build tools rapidly mid-conflict, and when active, MiniFast gave hackers full remote control via cmd.exe while hiding its traffic by impersonating a Google Chrome browser.

In April, the group abandoned emails for SEO poisoning. They built a fake website, getsqldevelopercom, to mimic Oracle’s SQL Developer software. By registering dozens of connected domains and using keyword stuffing, they pushed the scam site to the top of Bing and DuckDuckGo results, tricking developers into downloading the MiniFast backdoor directly.

2026 campaign timeline (Source: Check Point Research)

The Verdict

Check Point Research noted that wartime pressures actually accelerated the group’s capabilities. By mixing AI-driven coding with public search engine manipulation, Nimbus Manticore skipped targeted emails entirely to compromise systems faster, showing an expansion of their ambitions well beyond regional spying.