Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Aug 26, 2026
- Feed role
- C2
- Host form
- 0 IP / 14 hostnames
MiniFast, also known as MiniUpdate and sometimes referred to as Retrograde in overlapping reporting, is a Windows backdoor used by the Iranian state-sponsored threat actor Nimbus Manticore, which has been linked to the IRGC and is also tracked as UNC1549.
Profile source: Mallory opens in a new tabMiniFast
MiniFast, also known as MiniUpdate and sometimes referred to as Retrograde in overlapping reporting, is a Windows backdoor used by the Iranian state-sponsored threat actor Nimbus Manticore, which has been linked to the IRGC and is also tracked as UNC1549. It emerged in 2026 as a successor to the group’s earlier MiniJunk malware and was deployed in campaigns targeting aviation and software-sector victims across the United States, Europe, the Middle East, Saudi Arabia, and Australia, with broader reporting tying the actor to operations against additional sectors and regions.
MiniFast is designed for long-term covert access and remote operator control. It performs initial host reconnaissance, beacons system information to command infrastructure, and then enters a tasking loop to receive and execute commands. Reported functionality includes remote command execution, file and directory management, process and drive enumeration, file upload and download, data exfiltration, DLL loading, archive creation, process termination, persistence through scheduled tasks, and attempted privilege escalation including use of runas or UAC-elevation requests. It also supports configurable polling intervals and jitter to vary beacon timing.
The malware has been described as a 64-bit Windows DLL backdoor that communicates with command infrastructure over HTTP or JSON-based channels while masquerading as legitimate Chrome browser traffic through its user-agent. In observed intrusion chains, MiniFast was delivered through AppDomain hijacking, allowing malicious DLLs to execute inside legitimate .NET processes. Nimbus Manticore paired this execution method with trojanized software installers and trusted-looking binaries to reduce suspicion.
Observed delivery methods included career-themed phishing and fake meeting invitations leading to a trojanized Zoom installer, as well as SEO poisoning through a fake Oracle SQL Developer download site. In the Zoom-themed chain, loaders displayed benign-looking installation behavior, launched legitimate software components, and hijacked scheduled-task creation to establish persistence before executing MiniFast as the final payload. Later activity showed the actor broadening distribution through search-engine manipulation and fake software-download infrastructure.
Multiple researchers assessed that MiniFast’s code shows signs consistent with AI-assisted development, citing unusually verbose naming, extensive error handling, modular organization, and debug-style status messaging. The malware reflects a broader evolution in Nimbus Manticore tradecraft during 2026, combining social engineering, software impersonation, stealthy .NET execution abuse, and persistent remote access to support espionage-oriented operations against aviation, software, defense-adjacent, and other strategic targets.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
The Iran state-sponsored threat group Nimbus Manticore conducted attacks during the U.S.-Israel military campaign Operation Epic Fury targeting the U.S. aviation industry and others for deployment of a new AI-assisted backdoor called “MiniFast,” Check Point Research reported Friday.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.