Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1166+ Articles
126+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Iranian APT Targets Aviation, Software Companies With Updated Tools
Iranian APT Targets Aviation, Software Companies With Updated Tools
NEWS

Iranian APT Targets Aviation, Software Companies With Updated Tools

Nimbus Manticore, an Iranian advanced persistent threat group, has continued operations targeting aviation and software companies during and after the US military campaign against Iran, deploying updated tooling to maintain access.

Dylan H.

News Desk

May 26, 2026
4 min read

SecurityWeek reports that Nimbus Manticore, an Iranian advanced persistent threat (APT) group, has maintained an active campaign targeting aviation and software companies even during and in the aftermath of the US military campaign against Iran. Researchers tracking the group observed the use of updated malware tooling consistent with a deliberate effort to preserve long-term access within targeted organizations despite significant geopolitical disruption.

Threat Actor Profile: Nimbus Manticore

Nimbus Manticore is an Iranian state-aligned threat actor with a documented history of targeting aerospace, defense, and technology organizations. The group's operations align with Iranian strategic intelligence priorities — gathering technical and operational data from sectors where Iran seeks to close knowledge gaps or monitor adversary capabilities.

The group has demonstrated operational persistence, continuing to run active intrusion campaigns even during periods of significant pressure or geopolitical tension that might typically force a pause in offensive cyber operations. The continuation of activity during and after a US military campaign against Iran represents a notable escalation in operational tempo and signals the group's tasking reflects high-priority state intelligence objectives.

Updated Toolset

Researchers identified that Nimbus Manticore has updated its malware toolkit to evade detection and maintain persistence on previously compromised systems. While specific technical indicators are expected to be published in follow-on research, the updated tooling reportedly includes:

  • Modified backdoor variants with altered signatures and obfuscation to bypass existing detection rules
  • Revised command-and-control (C2) infrastructure to avoid blocklisted domains and IP ranges used in prior campaigns
  • Updated persistence mechanisms targeting legitimate system processes and scheduled tasks to blend with normal operating system behavior

This pattern of iterative tool evolution in response to detection and disruption is characteristic of well-resourced state-sponsored actors with dedicated development pipelines.

Targeted Sectors

The confirmed targeting of aviation and software development companies reflects two distinct strategic objectives:

Aviation Sector — Iran has long sought to circumvent Western sanctions on aviation parts and technology. Intelligence collected from aviation targets enables procurement of restricted components, insight into maintenance practices, and monitoring of Western aerospace capabilities. The aviation sector also represents critical national infrastructure in targeted countries, making it a strategic espionage and potential pre-positioning target.

Software Companies — Software firms represent a force-multiplier target. Compromising a software vendor can provide access to the vendor's customers through supply chain attacks, access to proprietary algorithms and intellectual property, and insight into software used by other targeted organizations.

Operational Context

The timing of continued Nimbus Manticore operations during a US military campaign against Iran carries strategic significance. The persistence suggests:

  1. Pre-positioned access — The group likely maintained dormant implants in previously compromised networks that can be reactivated without new initial access operations
  2. Resilient C2 infrastructure — Updated tooling and infrastructure indicates contingency planning for operational disruption
  3. High-priority tasking — The continued risk-taking during a period of elevated geopolitical tension signals that the intelligence collection mandate outweighs operational security concerns

Defense Recommendations

Organizations in the aviation and software sectors, particularly those with US government contracts or defense supply chain relationships, should review their threat exposure against Iranian APT TTPs:

  • Audit for dormant implants — Conduct retrospective log analysis and endpoint hunting for indicators associated with known Nimbus Manticore campaigns
  • Review privileged access — Enumerate service accounts and privileged identities for signs of compromise or persistence mechanisms
  • Monitor outbound DNS and HTTP — Iranian APT groups frequently use DNS tunneling and HTTP-based C2; behavioral analytics on outbound traffic can surface anomalous patterns
  • Patch internet-facing systems — Iranian APT groups routinely exploit unpatched VPN gateways, web application flaws, and remote access tools for initial access
  • Enable multi-factor authentication — Credential theft via phishing remains a primary initial access vector for Iranian threat actors

Source: SecurityWeek

#APT#Iran#Aviation#Espionage#Nation-State#Threat Intelligence#Malware

Related Articles

Russia's Forest Blizzard Harvests Logins via SOHO Router DNS Poisoning

Russia's APT28 (Forest Blizzard) is conducting a malwareless espionage campaign by modifying a single DNS setting in vulnerable SOHO routers to silently...

6 min read

Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign

Three threat activity clusters aligned with China jointly targeted a Southeast Asian government organization in a complex, well-resourced espionage...

5 min read

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

The Belarus-aligned Ghostwriter APT (UAC-0057/UNC1151) has launched a new phishing campaign impersonating Prometheus, a Ukrainian e-learning platform, to...

3 min read
Back to all News