News Room
16
Share
mediumCyber Espionage

Iranian APT Nimbus Manticore Escalates Cyber Espionage in Western Europe

Nimbus Manticore, an Iranian state-aligned APT, has intensified cyber espionage targeting defense and aerospace sectors in Western Europe since early 2025, employing sophisticated spear-phishing and custom malware.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Iranian APT Nimbus Manticore Escalates Cyber Espionage in Western Europe for ₿ 0.10 BTC. Contact us.

19 March 2026Last updated 19 March 20265 min readRaptor Cyber Intelligence
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
Medium
Actor Type:
APT
Geography:
Western Europe
Confidence:
Confirmed
Source:
Raptor Cyber Intelligence
Read Time:
5 min

Executive Summary

Since early 2025, the Iranian state-aligned advanced persistent threat (APT) group known as Nimbus Manticore has significantly intensified its cyber espionage activities targeting defense and aerospace sectors in Western Europe. This escalation is characterized by highly targeted spear-phishing campaigns, the deployment of custom malware, and advanced evasion techniques designed to maintain persistent access to victim networks.

Operational Overview

Nimbus Manticore's operations are marked by a strategic shift towards Western European targets, particularly within the defense and aerospace industries. The group employs spear-phishing emails that impersonate human resources recruiters from prominent companies such as Boeing, Airbus, and Rheinmetall. These emails direct recipients to counterfeit career portals built with React, which, upon interaction, deliver malicious ZIP archives containing malware payloads. The malware utilizes novel dynamic-link library (DLL) sideloading techniques to exploit undocumented Windows NT APIs, manipulating the DLL search path to execute malicious code without detection. This multi-stage infection chain underscores the group's commitment to sophisticated intrusion methods.

The primary malware utilized in these campaigns includes the MiniJunk backdoor and the MiniBrowse stealer. MiniJunk is designed for persistent access, while MiniBrowse focuses on data exfiltration. Both tools are characterized by advanced obfuscation and evasion tactics, such as compiler-level code obfuscation and the use of Cloudflare and Azure-backed command-and-control (C2) infrastructure, which enhances resilience against detection and takedown efforts. Additionally, the group employs stolen digital certificates to further legitimize their malicious activities and evade security measures.

Tactics, Techniques, and Procedures (TTPs)

Nimbus Manticore's TTPs align with those of other Iranian APT groups, including Charming Kitten (APT35) and MuddyWater (APT34). These groups are known for their use of spear-phishing campaigns, custom malware, and advanced evasion techniques. The group's focus on defense and aerospace sectors is consistent with Iran's strategic interests in these industries. The use of sophisticated spear-phishing tactics and custom malware indicates a high level of operational maturity and resource investment.

Implications and Recommendations

The escalation of Nimbus Manticore's cyber espionage activities poses significant risks to organizations within the defense and aerospace sectors in Western Europe. The group's advanced techniques and persistent access capabilities suggest a long-term strategic objective to gather sensitive information and intellectual property. Organizations are advised to implement comprehensive security measures, including regular security awareness training to recognize spear-phishing attempts, robust email filtering systems, and continuous monitoring for unusual network activities. Additionally, maintaining up-to-date software and systems, along with employing advanced endpoint detection and response solutions, can aid in the early detection and mitigation of such sophisticated threats.

Conclusion

Nimbus Manticore's intensified cyber espionage campaigns in Western Europe reflect a growing sophistication in state-sponsored cyber operations. The group's targeted approach, advanced malware deployment, and evasion techniques underscore the need for heightened vigilance and proactive defense strategies within the affected sectors.

(hendryadrian.com)

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo