INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning

| 2026-05-26 09:10 MEDIUM HIGH PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
Iranian state-aligned hackers, affiliated with the IRGC and tracked as Nimbus Manticore or UNC1549, launched a phishing and SEO poisoning campaign targeting US aviation between February and April 2026. The attackers impersonated aviation firms and software providers across the US, Europe, and the Middle East, using tactics such as career-themed phishing, trojanized Zoom installers, ZIP archives hosted on OnlyOffice, AppDomain hijacking, and a previously undocumented backdoor called MiniFast. This campaign coincided with Operation Epic Fury, the US military campaign launched on February 28. The attackers registered dozens of domains linking to a bogus site, filled its pages with search keywords, and used search engine poisoning for the first time, marking a notable shift in their tactics.
Technical Mitigations AI-generated
• Patch Oracle's SQL Developer database tool to prevent search engine poisoning. • Block domains linked to the bogus site used for SEO poisoning and phishing campaigns. • Use AppDomain hijacking detection techniques to identify malicious DLL loading into trusted .NET applications.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Epic FuryOperation Epic Fury
Target & Sectors
NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE MIDDLE_EAST MIDDLE_EAST telecommunicationstelecommunications aviationaviation defensedefense
Incident Timeline
‎April 2026
Iran-linked hackers, tracked as UNC1549, launched a phishing and SEO poisoning campaign impersonating US aviation firms and software providers in April 2026.
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources
Infosecurity-Magazine 2026-05-26
Infosecurity-Magazine 2026-05-26