Dossier
UNC1549
Coverage of UNC1549 in the Nexus archive.
- Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
Iranian state-sponsored hackers, part of the Nimbus Manticore group, are deploying MiniFast and MiniJunk V2 malware through phishing and SEO poisoning attacks targeting aviation and software sectors in the U.S., Europe, and the Middle East. The campaign follows a U.S.-Israeli military operation against Iran in late February 2026.