MiniFast, also known as MiniUpdate and sometimes referred to as Retrograde in overlapping reporting, is a Windows backdoor used by the Iranian state-sponsored threat actor Nimbus Manticore, which has been linked to the IRGC and is also tracked as UNC1549. It emerged in 2026 as a successor to the group’s earlier MiniJunk malware and was deployed in campaigns targeting aviation and software-sector victims across the United States, Europe, the Middle East, Saudi Arabia, and Australia, with broader reporting tying the actor to operations against additional sectors and regions.
MiniFast is designed for long-term covert access and remote operator control. It performs initial host reconnaissance, beacons system information to command infrastructure, and then enters a tasking loop to receive and execute commands. Reported functionality includes remote command execution, file and directory management, process and drive enumeration, file upload and download, data exfiltration, DLL loading, archive creation, process termination, persistence through scheduled tasks, and attempted privilege escalation including use of runas or UAC-elevation requests. It also supports configurable polling intervals and jitter to vary beacon timing.
The malware has been described as a 64-bit Windows DLL backdoor that communicates with command infrastructure over HTTP or JSON-based channels while masquerading as legitimate Chrome browser traffic through its user-agent. In observed intrusion chains, MiniFast was delivered through AppDomain hijacking, allowing malicious DLLs to execute inside legitimate .NET processes. Nimbus Manticore paired this execution method with trojanized software installers and trusted-looking binaries to reduce suspicion.
Observed delivery methods included career-themed phishing and fake meeting invitations leading to a trojanized Zoom installer, as well as SEO poisoning through a fake Oracle SQL Developer download site. In the Zoom-themed chain, loaders displayed benign-looking installation behavior, launched legitimate software components, and hijacked scheduled-task creation to establish persistence before executing MiniFast as the final payload. Later activity showed the actor broadening distribution through search-engine manipulation and fake software-download infrastructure.
Multiple researchers assessed that MiniFast’s code shows signs consistent with AI-assisted development, citing unusually verbose naming, extensive error handling, modular organization, and debug-style status messaging. The malware reflects a broader evolution in Nimbus Manticore tradecraft during 2026, combining social engineering, software impersonation, stealthy .NET execution abuse, and persistent remote access to support espionage-oriented operations against aviation, software, defense-adjacent, and other strategic targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Iran state-sponsored threat group Nimbus Manticore conducted attacks during the U.S.-Israel military campaign Operation Epic Fury targeting the U.S. aviation industry and others for deployment of a new AI-assisted backdoor called “MiniFast,” Check Point Research reported Friday.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
For the first time, we observed the use of SEO poisoning as an additional malware delivery method... the actor abuses search engine optimization techniques by registering dozens of domains that link to the bogus domain, getsqldeveloper[.]com.
Check Point said Nimbus Manticore has shifted tactics in its most recent attacks... using search engine optimization (SEO) poisoning to impersonate the software Oracle SQL Developer and spread MiniFast... Keyword stuffing of phrases such as “download SQL Developer” and “SQL Developer free” was also used to help the fake website surface high in search results for engines such as Bing and DuckDuckGo.
Both waves of attacks utilized career-themed phishing lures for initial access... As in previous attacks, Nimbus Manticore used career-themed phishing lures to spread MiniFast during Operation Epic Fury, specifically impersonating a U.S. domestic airline. Victims were lured to install a trojanized version of the legitimate Zoom installer after clicking a fake meeting invitation link.
The installer was not a crude knockoff; it demonstrated detailed knowledge of the legitimate Zoom installation process, even monitoring for the creation of a specific scheduled task that Zoom normally generates during setup, then silently hijacking that task to establish persistence without triggering obvious alarms.
It then monitors for the creation of a scheduled task — a part of the legitimate Zoom installation process — and modifies this task to load the second-stage components... Prior to executing the payload, the loader ensures that the hosting process name is update.exe and the parent process is svchost.exe to maintain stealth and persistence via the scheduled task... The backdoor supports commands for a wide range of actions including... creation of an additional scheduled task.
The backdoor supports commands for a wide range of actions including file and folder management and exfiltration, file download from the C2, shell command execution...
The installer was not a crude knockoff; it demonstrated detailed knowledge of the legitimate Zoom installation process, even monitoring for the creation of a specific scheduled task that Zoom normally generates during setup, then silently hijacking that task to establish persistence without triggering obvious alarms.
It then monitors for the creation of a scheduled task — a part of the legitimate Zoom installation process — and modifies this task to load the second-stage components... Prior to executing the payload, the loader ensures that the hosting process name is update.exe and the parent process is svchost.exe to maintain stealth and persistence via the scheduled task... The backdoor supports commands for a wide range of actions including... creation of an additional scheduled task.
The installer was not a crude knockoff; it demonstrated detailed knowledge of the legitimate Zoom installation process, even monitoring for the creation of a specific scheduled task that Zoom normally generates during setup, then silently hijacking that task to establish persistence without triggering obvious alarms.
It then monitors for the creation of a scheduled task — a part of the legitimate Zoom installation process — and modifies this task to load the second-stage components... Prior to executing the payload, the loader ensures that the hosting process name is update.exe and the parent process is svchost.exe to maintain stealth and persistence via the scheduled task... The backdoor supports commands for a wide range of actions including... creation of an additional scheduled task.
The loader itself is lightly obfuscated. Most readable strings are decrypted at runtime using a simple combination of ROT13 encoding and reversed-string transformations.
Victims were lured to install a trojanized version of the legitimate Zoom installer... AppDomain hijacking is again used to load the second-stage loader Updater.dll via the Setup.exe binary — now renamed to Update.exe... The malware impersonates a Chrome browser user agent to blend in with legitimate traffic.
At the beginning of its execution, the loader performs a simple anti-analysis validation intended to evade sandbox environments and automated dynamic analysis systems. The malware only continues execution if: The hosting process name is update.exe The parent process is svchost.exe
Before entering its tasking loop, the malware performs basic host reconnaissance by collecting information such as the username, hostname, and domain info.
The commands supported by the backdoor are varied, enabling file operations, directory listings, process enumeration
MiniFast performs system reconnaissance and then awaits commands from the C2 server...
The commands supported by the backdoor are varied, enabling file operations, directory listings
At the beginning of its execution, the loader performs a simple anti-analysis validation intended to evade sandbox environments and automated dynamic analysis systems. The malware only continues execution if: The hosting process name is update.exe The parent process is svchost.exe
MiniFast, the successor of MiniJunk, enables extensive control of the victim’s machine through API-based communications with the attacker’s command-and-control (C2) server... MiniFast performs system reconnaissance and then awaits commands from the C2 server, transmitting data in the JSON format. The malware impersonates a Chrome browser user agent to blend in with legitimate traffic.
To blend into legitimate network traffic, the malware impersonates a Chrome browser using the following hardcoded User-Agent string: Mozilla/5.0 ... Chrome/146.0.0.0 Safari/537.36 | The implant communicates with its C2 (command and control) infrastructure using an API-style architecture with JSON-formatted data exchanges... The backdoor implements several structured HTTP endpoints throughout the infection lifecycle.
Two other malware families delivered as part of the attacks are BridgeHead ("unbcl.dll"), a SOCKS5 tunnel proxy... and ArcBridge, another WebSocket tunneling tool...
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/tool family mentioned only for functional comparison with BridgeHead.
AI-assisted backdoor used by Nimbus Manticore that provides extensive control of infected machines via API-based C2 communications. It performs system reconnaissance, waits for commands, transmits data in JSON, impersonates a Chrome user agent, and supports file/folder management and exfiltration, file download, shell command execution, and creation of an additional scheduled task. It was delivered via career-themed phishing with a trojanized Zoom installer and later via SEO poisoning through fake Oracle SQL Developer sites.
A newly observed backdoor/RAT attributed to Nimbus Manticore. It supports file operations, process management, privilege escalation, and DLL loading, and the report says it appears to incorporate AI-assisted development practices.
A fully featured backdoor/RAT used for long-term persistence and remote command execution. It communicates over HTTP to fetch tasks, upload execution results, exfiltrate files, download additional payloads, beacon host information, perform file and process operations, execute commands, load DLLs, create ZIP archives, establish persistence via scheduled tasks, and use runas for privilege escalation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.