INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Nimbus Manticore Exploits Zoom with AI-Assisted Trojan Installers

| 2026-05-27 18:08 MEDIUM HIGH
Executive Summary AI-generated
The threat actor, known as Nimbus Manticore, has been quietly expanding its targets beyond Israel and the UAE to hit aviation and software firms in the US. The group's most recent campaign began on May 27, 2026, when it launched a real Zoom installer (Zoom_cm.exe) to hide an attack that had already compromised devices from unofficial sites earlier this year. This malware hijacked a Windows scheduled task (ZoomUpdateTaskUser), allowing hackers full remote control via cmd.exe while hiding its traffic by impersonating a Google Chrome browser. The threat actor's tactics, including AppDomain hijacking and fake job offers on OnlyOffice, have been used to target workers in Saudi Arabia and Australia with fake Zoom invites.
Technical Mitigations AI-generated
* Use a reputable antivirus software: Install and regularly update an anti-virus program to protect against malware, including the Nimbus Manticore Trojanized Zoom installers. * Keep your operating system and browser up-to-date: Ensure that all operating systems, browsers, and plugins are current with the latest security patches to prevent exploitation of known vulnerabilities. * Use strong passwords and enable two-factor authentication (2FA): Create unique, complex passwords for all accounts, and consider enabling 2FA whenever possible to add an extra layer of security against unauthorized access. * Be cautious when clicking on links or opening attachments: Avoid suspicious emails, links, or attachments that may contain malware or phishing scams. Instead, verify the authenticity of the link before clicking on it. * Regularly back up your data: Make sure you have a recent backup of important files and data to prevent loss in case of an attack or system failure. Additionally, consider implementing additional security measures such as: * Monitoring network traffic for suspicious activity * Using a firewall to block unauthorized access * Regularly scanning systems for malware using anti-virus software It's also essential to stay informed about the latest threat intelligence and best practices for cybersecurity.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Epic FuryOperation Epic Fury
Target & Sectors
GCC GCC AFRICA AFRICA NORTH_AMERICA NORTH_AMERICA EUROPE EUROPE telecommunicationstelecommunications aviationaviation defensedefense
Incident Timeline
‎February 2026
Threat actors used a Trojanized Zoom installer to target aviation and software firms in the US.
target_region Saudi Arabia
target_region Australia
organisation Fake Job Offers
organisation CPR
organisation OnlyOffice
organisation UAE
organisation Setup.exe
organisation Microsoft
organisation ZIP
organisation AppDomain
‎28 February 2026
Nimbus Manticore exploited vulnerabilities in Zoom to install Trojanized installers on US firms targeted by Operation Epic Fury.
campaign Operation Epic Fury
‎the end of February 2026
Threat actors used a Trojanized Zoom installer to target US firms during Operation Epic Fury.
target_region Iran, Islamic Republic of
target_region United States
campaign Operation Epic Fury
‎March 2026
Threat actors used Zoominstall64.zip to target US firms, deploying a fake website getsqldevelopercom and MiniFast backdoor via InitInstall.dll.
observable Zoominstall64.zip
organisation Search Engine Tricks MiniFast
infrastructure Windows
organisation getsqldevelopercom
organisation Oracle’s
organisation SQL
‎between February and April 2026-
Nimbus Manticore exploited vulnerabilities in Zoom to install Trojanized installers on US firms' systems between February and April 2026.
campaign Operation Epic Fury
‎2026/05/27
Iran's Nimbus Manticore used fake Zoom installers and SEO poisoning to target US firms.
organisation Nimbus Manticore Used
organisation APT
organisation Islamic Revolutionary Guard Corps
organisation CheckPoint
organisation Nimbus Manticore
organisation Check Point Research
organisation the Islamic Revolutionary Guard Corps
organisation IRGC
organisation Check Point
organisation Fake Zoom Installers
organisation SEO
organisation UAE
organisation OnlyOffice
organisation SecurityAffairs
organisation Microsoft
organisation AppDomain
organisation DLL
organisation Nimbus Manticore’s
organisation Nimbus Manticore Expanded
organisation API
organisation getsqldeveloper[.]com
organisation Oracle’s SQL Developer
organisation YARA
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product