Skip to content

MiniFast

MiniFast, also known as MiniUpdate and sometimes referred to as Retrograde in overlapping reporting, is a Windows backdoor used by the Iranian state-sponsored threat actor Nimbus Manticore, which has been linked to the IRGC and is also tracked as UNC1549.

Profile source: Mallory opens in a new tab

MiniFast

Family profile

MiniFast, also known as MiniUpdate and sometimes referred to as Retrograde in overlapping reporting, is a Windows backdoor used by the Iranian state-sponsored threat actor Nimbus Manticore, which has been linked to the IRGC and is also tracked as UNC1549. It emerged in 2026 as a successor to the group’s earlier MiniJunk malware and was deployed in campaigns targeting aviation and software-sector victims across the United States, Europe, the Middle East, Saudi Arabia, and Australia, with broader reporting tying the actor to operations against additional sectors and regions.

MiniFast is designed for long-term covert access and remote operator control. It performs initial host reconnaissance, beacons system information to command infrastructure, and then enters a tasking loop to receive and execute commands. Reported functionality includes remote command execution, file and directory management, process and drive enumeration, file upload and download, data exfiltration, DLL loading, archive creation, process termination, persistence through scheduled tasks, and attempted privilege escalation including use of runas or UAC-elevation requests. It also supports configurable polling intervals and jitter to vary beacon timing.

The malware has been described as a 64-bit Windows DLL backdoor that communicates with command infrastructure over HTTP or JSON-based channels while masquerading as legitimate Chrome browser traffic through its user-agent. In observed intrusion chains, MiniFast was delivered through AppDomain hijacking, allowing malicious DLLs to execute inside legitimate .NET processes. Nimbus Manticore paired this execution method with trojanized software installers and trusted-looking binaries to reduce suspicion.

Observed delivery methods included career-themed phishing and fake meeting invitations leading to a trojanized Zoom installer, as well as SEO poisoning through a fake Oracle SQL Developer download site. In the Zoom-themed chain, loaders displayed benign-looking installation behavior, launched legitimate software components, and hijacked scheduled-task creation to establish persistence before executing MiniFast as the final payload. Later activity showed the actor broadening distribution through search-engine manipulation and fake software-download infrastructure.

Multiple researchers assessed that MiniFast’s code shows signs consistent with AI-assisted development, citing unusually verbose naming, extensive error handling, modular organization, and debug-style status messaging. The malware reflects a broader evolution in Nimbus Manticore tradecraft during 2026, combining social engineering, software impersonation, stealthy .NET execution abuse, and persistent remote access to support espionage-oriented operations against aviation, software, defense-adjacent, and other strategic targets.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Aug 26, 2026
Feed role
C2
Host form
0 IP / 14 hostnames

Leading locations

  • US9

Leading providers

  • Microsoft Corporation7
  • Cloudflare, Inc.2

Infrastructure traits

  • Hosting 9
  • Anycast 2
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
Nimbus Manticore

The Iran state-sponsored threat group Nimbus Manticore conducted attacks during the U.S.-Israel military campaign Operation Epic Fury targeting the U.S. aviation industry and others for deployment of a new AI-assisted backdoor called “MiniFast,” Check Point Research reported Friday.

MITRE ATT&CK

MiniFast in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.