MiniUpdate RAT Leverages Azure for Targeted Espionage Campaigns
Key Takeaways An Iran-linked threat actor, Screening Serpens (aka UNC1549, Smoke Sandstorm, Iranian Dream Job), is actively deploying two advanced Remote Access Trojans (RATs), MiniUpdate and...
Key Takeaways
- An Iran-linked threat actor, Screening Serpens (aka UNC1549, Smoke Sandstorm, Iranian Dream Job), is actively deploying two advanced Remote Access Trojans (RATs), MiniUpdate and MiniJunk V2.
- The targeted espionage campaigns primarily focus on technology professionals in the United States, Israel, and the United Arab Emirates.
- The attackers leverage sophisticated techniques including AppDomainManager hijacking, DLL sideloading, and Azure-hosted command-and-control (C2) infrastructure to evade detection.
- Initial access is gained through highly convincing spear-phishing lures disguised as recruitment offers or software installers.
- Organizations in critical sectors like aerospace, defense, telecommunications, and technology are strongly advised to enhance their detection capabilities beyond signature-based methods.
Technology professionals across the United States, Israel, and the United Arab Emirates are currently facing a heightened threat from a series of targeted espionage campaigns. These attacks employ the advanced MiniUpdate Remote Access Trojan (RAT), which leverages Microsoft Azure cloud infrastructure for its command-and-control (C2) communications, as detailed in a recent analysis by Unit 42, the threat intelligence arm of Palo Alto Networks.
Table Of Content
The malicious activity, attributed to an Iran-linked hacking group, began as early as mid-February 2026 and has shown continued expansion, with new samples observed through mid-April. Researchers suggest this surge in operations aligns closely with a regional conflict in the Middle East that commenced on February 28, 2026.
The group responsible for these intrusions is known as Screening Serpens, also tracked under the aliases UNC1549, Smoke Sandstorm, and Iranian Dream Job. Active since at least 2022, Screening Serpens initially concentrated its efforts on targets within the Middle East before expanding its reach into Western Europe in late 2025. The current campaigns feature six newly discovered RAT variants, categorized into two distinct malware families: the novel MiniUpdate and an enhanced version, MiniJunk V2.
Analysts at Unit 42 identified these variants and assessed with moderate-to-high confidence that Screening Serpens is orchestrating the operation. According to their report shared with Cyber Security News (CSN), both malware families are delivered via spear-phishing attempts that masquerade as legitimate brands and recruitment platforms. Victims are enticed by fake job applications or spoofed meeting invitations designed to appear authentic. Once a target opens the malicious archive and executes the embedded file, the infection chain silently initiates, providing no visual indication of compromise to the user.
MiniUpdate RAT Leverages Azure-Hosted C2 Domains
The MiniUpdate RAT represents the more sophisticated of the two malware families. It employs an advanced technique known as AppDomainManager hijacking. This method involves modifying a legitimate configuration file to instruct the .NET runtime environment to disable its inherent security features before the host application fully loads. This critical step allows the malware payload to operate within an environment where standard security monitoring tools are effectively neutralized.
Specifically, the configuration disables Event Tracing for Windows (ETW), a vital telemetry source typically used by security software to detect anomalous behavior, and also circumvents digital signature verification. To maintain persistence across system reboots, the malware establishes a scheduled task configured to execute daily at 09:30 local time. Its command and control traffic is routed through Azure-hosted domains, each uniquely assigned to a specific target. This individualized C2 infrastructure strategy aims to prevent a single detection point from revealing the broader operational network.
In March, a campaign targeting U.S. entities delivered the MiniUpdate RAT within an archive disguised as airline recruitment materials, featuring fabricated job descriptions for senior technical positions.
During the same month, a campaign in Israel utilized an archive impersonating a video conferencing installer. This iteration presented a convincing spoofed loading screen to the user while the malware silently deployed in the background.
MiniJunk V2: Obfuscated Backdoor Targeting Tech and Defense
The MiniJunk V2 family, first detected on February 17, 2026, employs a different strategy for stealth. It significantly inflates its file size to approximately 12 megabytes by embedding thousands of irrelevant code strings from various programming languages, including Java and Python. This “noise” is designed to exceed the scanning limits of certain automated security tools and overwhelm analysis software with extraneous data, thereby complicating manual investigation.
MiniJunk V2 utilizes a two-layered DLL sideloading mechanism to deploy its payload. It then connects to five Azure-hosted command servers, whose domain names are crafted to mimic legitimate Windows service processes. A variant observed in the March U.S. campaign included a hard-coded date check, preventing the RAT from activating before March 27, 2026, at 13:30 UTC. This delay tactic renders early sandbox analysis largely ineffective. Concurrently, a fake “Meeting Room” window is displayed to the victim to divert attention from the malicious activities occurring in the background.
What You Should Do
- Enhance Endpoint Detection: Configure Endpoint Detection and Response (EDR) tools to flag behaviors such as DLL sideloading and AppDomainManager hijacking as high-risk activities, rather than relying solely on signature-based detections.
- Monitor for Anomalous Module Loading: Implement monitoring for trusted binaries that load unsigned or otherwise unrecognized modules. This adds a crucial layer of defense against sophisticated malware evasion techniques.
- Exercise Caution with Unsolicited Communications: Organizations in sectors such as aerospace, defense, telecommunications, and technology should treat all unsolicited job applications, recruitment materials, or unexpected software update prompts with extreme suspicion. These remain the primary entry vectors for Screening Serpens.
- Employee Training: Conduct regular cybersecurity awareness training for employees, emphasizing the dangers of spear-phishing, social engineering, and the importance of verifying the legitimacy of all attachments and links before interacting with them.
- Implement Zero Trust Principles: Adopt a Zero Trust security model, which assumes no user or device is inherently trustworthy, regardless of its location relative to the network perimeter.
- Review Indicators of Compromise (IoCs): Integrate the provided IoCs (domains, URLs, and SHA256 hashes) into your security infrastructure (SIEM, EDR, firewalls) for proactive detection and blocking.
Indicators of Compromise (IoCs)
| Type | Indicator | Description |
|---|---|---|
| Domain | licencemanagers.azurewebsites[.]net | MiniJunk V2 C2 domain |
| Domain | LicenceSupporting.azurewebsites[.]net | MiniJunk V2 C2 domain |
| Domain | PeerDistSvcManagers.azurewebsites[.]net | MiniJunk V2 C2 domain |
| Domain | ThemesManagers.azurewebsites[.]net | MiniJunk V2 C2 domain |
| Domain | ThemesProviderManagers.azurewebsites[.]net | MiniJunk V2 C2 domain |
| Domain | NanoMatrix.azurewebsites[.]net | MiniJunk V2 US Campaign C2 |
| Domain | QuantumWeave.azurewebsites[.]net | MiniJunk V2 US Campaign C2 |
| Domain | ElementShift.azurewebsites[.]net | MiniJunk V2 US Campaign C2 |
| Domain | buisness-centeral.azurewebsites[.]net | MiniUpdate C2 domain |
| Domain | buisness-centeral-transportation.azurewebsites[.]net | MiniUpdate C2 domain |
| Domain | Buisness-centeral-transportation[.]com | MiniUpdate C2 domain |
| Domain | PremierHealthAdvisory[.]com | MiniUpdate UAE Campaign C2 |
| Domain | PremierHealthAdvisory.azurewebsites[.]net | MiniUpdate UAE Campaign C2 |
| Domain | Premier-HealthAdvisory.azurewebsites[.]net | MiniUpdate UAE Campaign C2 |
| Domain | Ramiltonsfinance[.]com | MiniUpdate Middle East Campaign C2 |
| Domain | Ramiltonsfinance.azurewebsites[.]net | MiniUpdate Middle East Campaign C2 |
| Domain | Ramiltons-finance.azurewebsites[.]net | MiniUpdate Middle East Campaign C2 |
| Domain | business-startup[.]org | Screening Serpens infrastructure |
| Domain | business-startup.azurewebsites[.]net | Screening Serpens infrastructure |
| Domain | docspace-y4cumb.onlyoffice[.]com | Payload delivery host (ONLYOFFICE) |
| Domain | docspace-twpf0e.onlyoffice[.]com | Payload delivery host (ONLYOFFICE) |
| URL | hxxps[:]//docspace-y4cumb.onlyoffice[.]com/storage/files/root/folder_3602000/file_3601577/v1/content.zip | MiniJunk V2 payload delivery URL |
| URL | hxxps[:]//docspace-twpf0e.onlyoffice[.]com/storage/files/root/folder_3765000/file_3764519/v1/content.zip | MiniJunk V2 US campaign delivery URL |
| URL | hxxps[:]//2117.filemail[.]com/api/file/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUm | MiniUpdate Israel campaign payload URL |
| SHA256 | 44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250 | MiniUpdate US campaign – initial archive |
| SHA256 | 332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17 | MiniUpdate US campaign – Hiring Portal.zip |
| SHA256 | 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 | MiniUpdate US campaign – UpdateChecker.dll |
| SHA256 | 38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d | MiniUpdate Israel campaign – initial archive |
| SHA256 | d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2 | MiniUpdate Israel campaign – UpdateChecker.dll |
| SHA256 | bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad | MiniUpdate UAE/Middle East – UpdateChecker.dll |
| SHA256 | 74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27 | MiniUpdate Middle East campaign |
| SHA256 | 9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84 | MiniJunk V2 Middle East – uevmonitor.dll |
| SHA256 | b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4 | MiniJunk V2 Middle East – unbcl.dll |
| SHA256 | 8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b | MiniJunk V2 US campaign – Portable Platform.zip |
| SHA256 | 43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa | MiniJunk V2 US campaign – Connection.dll |
| SHA256 | 9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1 | MiniJunk V2 US campaign – unbcl.dll |
| File Name | UpdateChecker.dll | MiniUpdate RAT core payload |
| File Name | uevmonitor.dll | MiniJunk V2 primary loader DLL |
| File Name | Connection.dll | MiniJunk V2 US campaign RAT payload |
| File Name | Hiring Portal.zip | Lure archive used in US/Israel campaigns |
| File Name | Portable platform.zip | Lure archive used in US MiniJunk V2 campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.