Last seven days
- First activity
- Sep 23, 2026
- Last activity
- Sep 23, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
MiniJunk is a Windows backdoor used by the Iranian threat actor Nimbus Manticore, which reporting also links or overlaps with UNC1549, Smoke Sandstorm, TA455, and Tortoiseshell, and is assessed as affiliated with the IRGC.
Profile source: Mallory opens in a new tabMiniJunk
MiniJunk is a Windows backdoor used by the Iranian threat actor Nimbus Manticore, which reporting also links or overlaps with UNC1549, Smoke Sandstorm, TA455, and Tortoiseshell, and is assessed as affiliated with the IRGC. It is described as an evolution of the earlier Minibike implant, also known as SlugResin. Reporting places MiniJunk in espionage campaigns from at least 2025 through 2026 targeting high-value organizations and professionals in aerospace, defense manufacturing, telecommunications, aviation, satellite, software, and related sectors across Western Europe, the Middle East, the United States, Saudi Arabia, Australia, Israel, and the UAE.
Observed delivery and execution methods include recruitment- and career-themed spear-phishing, fake career portals impersonating companies such as Boeing, Airbus, Rheinmetall, flydubai, Telespazio, and Safran, OnlyOffice-hosted archives, and trojanized installers. Multiple reports state that MiniJunk was delivered via DLL sideloading and AppDomain hijacking. In 2026 activity, a benign Microsoft-signed executable and malicious .config file were used to abuse the .NET runtime and load a rogue DLL. Other infection chains used Setup.exe to sideload a malicious userenv.dll, then launched SenseSampleUploader.exe to sideload xmllite.dll. Reporting also describes a previously undocumented technique in which the malware modified low-level process execution parameters, specifically the DLL search path via RTL_USER_PROCESS_PARAMETERS/DllPath, to force DLL loading from attacker-controlled paths.
MiniJunk establishes persistence by copying itself to %AppData%\\Local\\Microsoft\\MigAutoPlay\\ and creating scheduled-task or autorun execution for MigAutoPlay.exe. In some cases the persistent executable displayed a fake network error to reduce suspicion. One report notes MiniJunk hooks ExitProcess when running as MigAutoPlay.exe. The malware collects host identifiers including computer name and domain-qualified username, and communicates with multiple hardcoded HTTPS command-and-control servers, typically three to five in rotation for redundancy. Network data has been described as encoded rather than encrypted, including byte and string reversal.
Documented backdoor capabilities include system identification, file read/write, directory listing, file deletion, file move/rename, process creation, process listing or termination, DLL loading, and execution of additional payloads. Reporting consistently emphasizes strong anti-analysis measures: heavy compiler-level obfuscation, junk code insertion, control-flow obfuscation, opaque predicates, encrypted strings, and binary size inflation, with some researchers assessing the obfuscation may have been implemented through custom LLVM passes. Some campaigns also used valid SSL.com code-signing certificates to reduce detection.
MiniJunk was frequently deployed alongside MiniBrowse, a lightweight stealer targeting Chrome and Edge credentials. In 2026 reporting, MiniJunk was described as an older backdoor later supplanted in some campaign waves by MiniFast/MiniUpdate, while Unit 42 also referenced an updated MiniJunk V2. High-confidence infrastructure and infection artifacts mentioned in the reporting include persistence under %AppData%\\Local\\Microsoft\\MigAutoPlay\\, use of Setup.exe, userenv.dll, SenseSampleUploader.exe, xmllite.dll, and AppDomain hijacking chains involving malicious configuration files and loader DLLs.
Samples
Reported operators
The attacks, seen throughout the 2026 Iran war in March, followed previous campaigns throughout February using an older backdoor called MiniJunk.
The primary payload, dubbed MiniJunk, is an evolved version of the Minibike backdoor first documented in 2022. MiniJunk employs advanced obfuscation techniques... MiniJunk establishes persistence by copying itself to `%AppData%\Local\Microsoft\MigAutoPlay\` and creating a scheduled task... The backdoor supports commands like file reading, process creation, and DLL loading, communicating with multiple hardcoded C2 servers via HTTPS...
Over subsequent years, the group layered in additional tooling — MiniJunk, MiniBrowse, DCSyncer.Slick, DeepRoot, GhostLine, LightRail, and others...
Over subsequent years, the group layered in additional tooling — MiniJunk, MiniBrowse, DCSyncer.Slick, DeepRoot, GhostLine, LightRail, and others...
"userenv.dll is a TA455 custom backdoor termed MiniJunk in public reporting, a version of previously reported malware called MiniBike."
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.