INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning
| 2026-05-26 09:10 PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Iranian state-aligned hackers, affiliated with the IRGC and tracked as Nimbus Manticore or UNC1549, launched a phishing and SEO poisoning campaign targeting US aviation between February and April 2026. The attackers impersonated aviation firms and software providers across the US, Europe, and the Middle East, using tactics such as career-themed phishing, trojanized Zoom installers, ZIP archives hosted on OnlyOffice, AppDomain hijacking, and a previously undocumented backdoor called MiniFast. This campaign coincided with Operation Epic Fury, the US military campaign launched on February 28. The attackers registered dozens of domains linking to a bogus site, filled its pages with search keywords, and used search engine poisoning for the first time, marking a notable shift in their tactics.
Technical Mitigations AI-generated
• Patch Oracle's SQL Developer database tool to prevent search engine poisoning.
• Block domains linked to the bogus site used for SEO poisoning and phishing campaigns.
• Use AppDomain hijacking detection techniques to identify malicious DLL loading into trusted .NET applications.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Tactical Metrics
Intelligence Sources
Infosecurity-Magazine
2026-05-26
Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign
Infosecurity-Magazine
Infosecurity-Magazine
2026-05-26
Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign
Infosecurity-Magazine