<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Iran-Linked Hackers Target Europe With New Malware

Iranian hackers expand their reach, targeting European infrastructure with advanced malware, posing a significant threat to cybersecurity.
Content Team

Iranian cyber-espionage group "Nimbus Manticore" has expanded beyond the Middle East to target critical infrastructure in Denmark, Portugal, and Sweden. The IRGC-linked hackers are hitting defense manufacturing, telecommunications, and aviation companies using two new malware variants: "MiniJunk" and "MiniBrowse."

Their attacks start with fake HR recruitment emails appearing to come from companies like Airbus and Boeing. Victims are directed to phony job sites that download malicious archives disguised as hiring materials.

MiniJunk is a significantly upgraded backdoor that uses advanced obfuscation techniques, code signing, and multiple command servers to avoid detection. The malware can steal files, execute processes, and maintain persistent access to compromised systems.

Check Point researchers say the group's sophisticated tactics represent "a significant increase in the actor's abilities," making detection much harder for defenders.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo