Nimbus Manticore, an Iranian-nexus threat actor also tracked as UNC1549, has shifted its cyber espionage tactics.
Moving away from traditional career-themed phishing, the group is now exploiting search engine optimization (SEO) techniques to distribute a new malware strain called MiniFast.
Recent threat intelligence highlights how the group created a fake download page for SQL Developer, a popular database management tool, to trap unsuspecting victims.
This marks a significant evolution for the group, which traditionally targets the defense, aviation, and telecommunications sectors.
Hackers Abuse SEO Poisoning
In a recent wave of attacks, researchers uncovered a highly coordinated campaign that drove traffic to the malicious domain getsqldeveloper[.]com.
The threat actors registered dozens of secondary domains that pointed to this bogus site to boost its search engine ranking via link-based reputation signals artificially.
By heavily using keyword stuffing with phrases like “Download SQL Developer,” the malicious site ranked highly on major search engines such as Bing and DuckDuckGo.

When developers download the fake installer, it triggers a sophisticated multi-stage infection chain. A hallmark of Nimbus Manticore’s recent operations is the heavy use of AppDomain Hijacking.
This technique abuses legitimate .NET applications by placing a trojanized XML .config file next to a trusted Microsoft-signed binary.
When the user launches the application, the .NET runtime is tricked into loading a malicious DLL, allowing the attackers to execute code securely within a trusted process.

Before adopting SEO poisoning, the threat actor relied on weaponized Zoom installers. During these earlier attacks, the malware displayed a fake installation progress window while silently launching the real Zoom installer in the background.
To maintain persistence, the malware monitored the system for scheduled tasks created by Zoom.
It then hijacked the legitimate ZoomUpdateTaskUser task to launch the malicious payload instead, avoiding the creation of new, suspicious registry keys.

The ultimate goal of these infection chains is to deploy MiniFast, a 64-bit Windows PE DLL that serves as the group’s newest backdoor, replacing the older MiniJunk framework.
MiniFast is designed for long-term stealth, acting as a remote access tool that gives attackers deep control over compromised systems.
Checkpoint said in a report shared with CyberPress, the backdoor validates its environment before running, ensuring it is hosted by the correct update.exe process and launched by svchost.exe.
Once validated, MiniFast communicates with its command and control (C2) server using an API-style architecture. It formats data exchanges in JSON and impersonates a Google Chrome browser to blend seamlessly into regular web traffic.
Indicators of Compromise
| Indicator Type | Indicator Value | Description / Context |
|---|---|---|
| Domain | getsqldeveloper[.]com | Fake SQL Developer download page used for SEO poisoning and malware distribution. |
| File Name | Zoominstall64.zip | Malicious compressed archive masquerading as a Zoom installer. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.