The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following the joint U.S.-Israeli military campaign against the country in late February 2026.
The activity, besides embracing

source https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html

source https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html