INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Iranian APT Screening Serpens Espionage Campaigns

| 2026-05-22 13:00 MEDIUM MEDIUM
Executive Summary AI-generated
The Iran-nexus advanced persistent threat group, Screening Serpens, has been detected in recent months with a persistent threat profile. This cyberespionage group is aligned with Iranian intelligence objectives and has targeted entities across the US, Israel, and two additional Middle Eastern countries. The group's tactics include rotating C2 domains to impersonate health sector or financial entity targets, utilizing 18 distinct opcodes on command dispatchers in its April variants. Screening Serpens remains active, posing a threat with ongoing tracking efforts by Unit 42 researchers.
Technical Mitigations AI-generated
• Implement a robust security awareness training program for employees to educate them on the importance of social engineering attacks and how to identify suspicious emails or messages. • Conduct regular software updates and patches to ensure that all systems, networks, and applications are up-to-date with the latest security fixes and vulnerabilities. • Utilize advanced threat detection tools and technologies, such as machine learning-based solutions, to detect and respond to emerging threats in real-time.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign WhileCampaign WhileCampaign ThisCampaign ThisCampaign AttackersCampaign Attackers
Target & Sectors
NORTH_AMERICA NORTH_AMERICA MIDDLE_EAST MIDDLE_EAST EUROPE EUROPE defensedefense telecommunicationstelecommunications healthhealth aerospaceaerospace manufacturingmanufacturing technologytechnology
Incident Timeline
‎April 15 and 17, 2026
Threat actors used VirusTotal to target Israel and the United Arab Emirates in espionage campaigns against Iranian Advanced Persistent Threats.
target_region Israel
target_region United Arab Emirates
‎late 2025
The Screening Serpens APT group began preparing for its 2026 espionage campaigns in late 2025.
target_region MIDDLE_EAST
target_region EUROPE
organisation Check Point Research
‎Feb. 17, 2026
Threat actors used MiniJunk V2 to target a professional working in the technology sector in February's Middle Eastern conflict.
industry Technology
tactic Phishing
organisation February Middle Eastern Campaign
target_region MIDDLE_EAST
‎Feb. 17
The MiniJunk V2 family samples were uploaded on February 17 and March 27.
‎Feb. 28, 2026
Threat actors used Serens to target MIDDLE_EAST on Feb. 28, 2026, aligning closely with the regional conflict that started in the Middle East.
target_region MIDDLE_EAST
‎February 2026
Threat actors used advanced AppDomainManager hijacking to establish persistence and maintain full operational control over the exfiltration of sensitive data in Iranian APT Screening Serpens' 2026 espionage campaigns.
‎March 26, 2026
The attackers delivered the MiniUpdate malware variant via an archive file, impersonating a popular video conferencing platform.
target_region Israel
target_region United Arab Emirates
organisation ZIP
organisation PDF
organisation Initial Delivery and Targeted Recruitment Lures
‎no earlier than March 26, 2026
Threat actors deployed Iranian APT Screening Serpens malware no earlier than March 26, 2026.
‎March 27, 2026
The threat actor used the uevmonitor.dll assembly to initiate infection in a legitimate Setup.exe host process.
observable Platform.zip
observable Connection.dll
organisation UTC
organisation DocSpace
organisation Portal.zip
organisation Synchronize OS
organisation Unbcl.dll
organisation Technical Analysis
organisation .config file
organisation Technical Analysis of the Payload Serving
organisation Initial Access The
organisation Setup.exe
infrastructure Windows
organisation Microsoft Edge
organisation ONLYOFFICE
organisation Sideloading and Hijacking During
organisation SQL
organisation MB
organisation Cortex XDR
data_breach 12 MB
organisation GUI
organisation Chrome
‎March 27
The MiniJunk V2 family samples were uploaded on March 27.
‎late March 2026
Threat actors used VirusTotal to upload samples from organizations in the U.S. and Israel, targeting Iranian APTs known as Serpens during late March 2026.
source_region Israel
‎March 2026
The target received a phishing campaign targeting Iranian APT Screening Serpens, with the attackers using authentic video conferencing links to establish trust and deliver malicious payloads via third-party file-sharing services.
tactic Social Engineering
tactic T1684 - Social Engineering
organisation Initial Access Analysis
‎April 15, 2026
Threat actors used PremierHealthAdvisory[.]com and Ramiltonsfinance[.]com to target entities in the UAE, impersonating health sector entities.
target_region United Arab Emirates
tactic Impersonate
industry Health
organisation PremierHealthAdvisory[.]com
general_metric 18 distinct opcodes
‎April 17, 2026
The threat actor employed a .NET-specific code execution technique known as AppDomainManager hijacking to target entities in the UAE on April 17, 2026.
target_region United Arab Emirates
tactic Impersonate
industry Health
organisation PremierHealthAdvisory[.]com
general_metric 18 distinct opcodes
organisation UpdateChecker.dll
organisation update.exe.config Updater.dll
infrastructure Windows
organisation ETW
organisation EDR
infrastructure 5.0
infrastructure 10.0
infrastructure 537.36
infrastructure 146.0.0
organisation C2 Architecture and Network Execution
organisation Win64
organisation KHTML
organisation Digital
organisation InitInstall.dll
organisation Anti-Analysis Checks
organisation Updater.dll
organisation Core Functionality
organisation Pre-Main
organisation XML
organisation CLR
organisation API
organisation Microsoft
organisation UTF-8
organisation UI
organisation Operations
organisation OPSEC
organisation XOR
‎mid-April 2026
Additional samples from the UAE and another Middle Eastern entity were discovered in mid-April 2026.
target_region United Arab Emirates
organisation UAE
‎April 2026
The Iranian APT group Screening Serpens used a technique called AppDomainManager hijacking to infect targets, leveraging targeted spear phishing lures and DLL sideloading for execution.
organisation VirusTotal
organisation Additional References
organisation DLL
organisation Cortex
organisation MiniUpdate
organisation DNS Security
organisation Behavioral Threat Protection
organisation the Local Analysis
organisation Palo Alto Networks
organisation Cyber Threat Alliance
organisation CTA
‎between April 15 and April 17, 2026
Threat actors used a previously unknown Iranian Advanced Persistent Threat (APT) to target entities in the United Arab Emirates between April 15 and April 17, 2026.
source_region United Arab Emirates
‎between February and April 2026
Threat actors used a newly discovered remote access Trojan (RAT) variant to target Iranian entities between February and April 2026.
‎March 26, April 15 and April 17
Threat actors used the MiniUpdate family of software updates to upload tracking malware samples on March 26, April 15 and April 17.
‎2026/05/22
The incident involved bypassing signature validation in the .NET Common Language Runtime (CLR) to target entities in the United States, Israel, and the United Arab Emirates.
organisation APT
organisation Screening Serpens
organisation Smoke Sandstorm
organisation Tracking Iranian APT Screening Serpens
infrastructure Windows
infrastructure 0.30319
organisation privatePath="
organisation Bypassing
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎0.30319
Software Version
Metrics
infrastructure
‎5.0
Software Version
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
‎537.36
Software Version
Metrics
infrastructure
‎146.0.0
Software Version
Metrics
data_breach
12
Mb