L’attribution à Mirage Kitten repose sur des similarités structurelles avec le backdoor natif Retrograde/MiniFast.
MiniFast
MiniFast, also known as MiniUpdate and Retrograde, is a 64-bit Windows backdoor attributed to the Iranian IRGC-affiliated threat actor Nimbus Manticore (UNC1549).
Profile source: Mallory opens in a new tabMiniFast
Family profile
MiniFast, also known as MiniUpdate and Retrograde, is a 64-bit Windows backdoor attributed to the Iranian IRGC-affiliated threat actor Nimbus Manticore (UNC1549). It emerged in 2026 as a replacement for MiniJunk in espionage campaigns targeting aviation and software-sector organizations in the United States, Europe, the Middle East, Saudi Arabia, and Australia. MiniFast is deployed through career-themed spearphishing, trojanized installers abusing AppDomain hijacking, and SEO-poisoned websites impersonating legitimate software-download portals. The malware establishes long-term access through scheduled-task persistence and communicates with command-and-control infrastructure over HTTP using structured JSON-based tasking while impersonating Chrome browser traffic. It performs host reconnaissance; enumerates processes, drives, and directories; executes shell commands; manages, uploads, and downloads files; loads DLLs; creates archives; terminates processes; adjusts beacon timing; and can request elevation through Windows runas. Analyses have identified coding characteristics consistent with possible AI-assisted development, although this is an assessment rather than a confirmed development provenance.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Privilege Escalation
- Reconnaissance
Reported operators
Threat actors
2 named in public reportingAttribution of PollCat to Nimbus Manticore is supported by structural, command-fetching, beacon-timing, and command-set similarities between PollCat and MiniFast, a backdoor previously attributed to the group.
MITRE ATT&CK