Hackers Abuse SEO Poisoning To Spread Fake SQL Developer Malware

Nimbus Manticore, an Iranian-nexus threat actor also tracked as UNC1549, has shifted its cyber espionage tactics.

Moving away from traditional career-themed phishing, the group is now exploiting search engine optimization (SEO) techniques to distribute a new malware strain called MiniFast.

Recent threat intelligence highlights how the group created a fake download page for SQL Developer, a popular database management tool, to trap unsuspecting victims.

This marks a significant evolution for the group, which traditionally targets the defense, aviation, and telecommunications sectors.

Hackers Abuse SEO Poisoning

In a recent wave of attacks, researchers uncovered a highly coordinated campaign that drove traffic to the malicious domain getsqldeveloper[.]com.

The threat actors registered dozens of secondary domains that pointed to this bogus site to boost its search engine ranking via link-based reputation signals artificially.

By heavily using keyword stuffing with phrases like “Download SQL Developer,” the malicious site ranked highly on major search engines such as Bing and DuckDuckGo.

2026 campaign timeline during the ongoing military campaign (Source: checkpoint)
2026 campaign timeline during the ongoing military campaign (Source: checkpoint)

When developers download the fake installer, it triggers a sophisticated multi-stage infection chain. A hallmark of Nimbus Manticore’s recent operations is the heavy use of AppDomain Hijacking.

This technique abuses legitimate .NET applications by placing a trojanized XML .config file next to a trusted Microsoft-signed binary.

When the user launches the application, the .NET runtime is tricked into loading a malicious DLL, allowing the attackers to execute code securely within a trusted process.

ZIP file hosted on Onlyoffice (Source: checkpoint)
ZIP file hosted on Onlyoffice (Source: checkpoint)

Before adopting SEO poisoning, the threat actor relied on weaponized Zoom installers. During these earlier attacks, the malware displayed a fake installation progress window while silently launching the real Zoom installer in the background.

To maintain persistence, the malware monitored the system for scheduled tasks created by Zoom.

It then hijacked the legitimate ZoomUpdateTaskUser task to launch the malicious payload instead, avoiding the creation of new, suspicious registry keys.

Zip file masquerading as an Accenture job opportunity (Source: checkpoint)
Zip file masquerading as an Accenture job opportunity (Source: checkpoint)

The ultimate goal of these infection chains is to deploy MiniFast, a 64-bit Windows PE DLL that serves as the group’s newest backdoor, replacing the older MiniJunk framework.

MiniFast is designed for long-term stealth, acting as a remote access tool that gives attackers deep control over compromised systems.

Checkpoint said in a report shared with CyberPress, the backdoor validates its environment before running, ensuring it is hosted by the correct update.exe process and launched by svchost.exe.

Once validated, MiniFast communicates with its command and control (C2) server using an API-style architecture. It formats data exchanges in JSON and impersonates a Google Chrome browser to blend seamlessly into regular web traffic.

Indicators of Compromise

Indicator TypeIndicator ValueDescription / Context
Domaingetsqldeveloper[.]comFake SQL Developer download page used for SEO poisoning and malware distribution.
File NameZoominstall64.zipMalicious compressed archive masquerading as a Zoom installer.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories