An Iranian APT tracked as Nimbus Manticore has adopted new tactics and updated its arsenal in new intrusions targeting aviation and software companies, Check Point reports.
Also known as Bohrium, Smoke Sandstorm, TA455, and UNC1549, and active since at least 2022, Nimbus Manticore is believed to be a subgroup of Charming Kitten (APT35) and to have ties with Iran’s Islamic Revolutionary Guard Corps (IRGC).
Nimbus Manticore was previously seen targeting aerospace, aviation, and defense organizations in the Middle East and Europe with the MiniBike and MiniBus backdoors.
In November 2024, the group was blamed for adopting North Korea-linked Lazarus Group’s tactics in a Dream Job campaign targeting the aerospace industry.
Earlier this year, Google warned of the APT’s continuous targeting of organizations in the defense sector with fake job offers, and Check Point now says that the group’s activities have continued during and after the US military campaign against Iran that started in February 2026.








