Skip to content

MiniFast

MiniFast, also known as MiniUpdate and Retrograde, is a 64-bit Windows backdoor attributed to the Iranian IRGC-affiliated threat actor Nimbus Manticore (UNC1549).

Profile source: Mallory opens in a new tab

MiniFast

Family profile

MiniFast, also known as MiniUpdate and Retrograde, is a 64-bit Windows backdoor attributed to the Iranian IRGC-affiliated threat actor Nimbus Manticore (UNC1549). It emerged in 2026 as a replacement for MiniJunk in espionage campaigns targeting aviation and software-sector organizations in the United States, Europe, the Middle East, Saudi Arabia, and Australia. MiniFast is deployed through career-themed spearphishing, trojanized installers abusing AppDomain hijacking, and SEO-poisoned websites impersonating legitimate software-download portals. The malware establishes long-term access through scheduled-task persistence and communicates with command-and-control infrastructure over HTTP using structured JSON-based tasking while impersonating Chrome browser traffic. It performs host reconnaissance; enumerates processes, drives, and directories; executes shell commands; manages, uploads, and downloads files; loads DLLs; creates archives; terminates processes; adjusts beacon timing; and can request elevation through Windows runas. Analyses have identified coding characteristics consistent with possible AI-assisted development, although this is an assessment rather than a confirmed development provenance.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Reported operators

Threat actors

2 named in public reporting
Mirage Kitten

L’attribution à Mirage Kitten repose sur des similarités structurelles avec le backdoor natif Retrograde/MiniFast.

Nimbus Manticore

Attribution of PollCat to Nimbus Manticore is supported by structural, command-fetching, beacon-timing, and command-set similarities between PollCat and MiniFast, a backdoor previously attributed to the group.

MITRE ATT&CK

MiniFast in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.