Skip to content

Nimbus Manticore APT Uses Fake Jobs to Deliver Custom Malware

Gbhackers •Mayura Kathir • June 2, 2026

A newly observed cyber campaign linked to the Iran-aligned threat group Nimbus Manticore (also tracked as UNC1549 and Smoke Sandstorm) is targeting aerospace and defense organizations using a deceptive recruitment workflow that delivers custom malware through a sophisticated sideloading chain. The operation highlights the group’s continued reliance on social engineering combined with stealthy execution techniques […]

Extracted Entities

Attack Types (1)

Countries (1)

Industries (2)