securityaffairs.com 5/26/2026, 9:18:45 AM · external

Iranian hackers use AI malware, SEO tricks in US aviation attacks

Iranian hackers use AI malware, SEO tricks in US aviation attacks
CyberSIXT Evidence Panel
Threat Actor
🇮🇷 UNC1549

THE article discusses Nimbus Manticore, an Iran-linked cyber threat group, which intensified its operations during the U.S. military operation against Iran in early 2026. Researchers from Check Point reported that the group employed innovative tactics including AI-assisted malware and SEO poisoning to enhance their attack methods.

The campaign manifested in three phases: 1) Malicious career offers luring software and aviation employees to download a malware-laden ZIP file; 2) A trojanized Zoom installer distributed through fake meeting invites; 3) Use of fake websites to distribute malware through SEO manipulation instead of traditional phishing techniques. The group demonstrated advanced capabilities like AI-assisted code generation and sought to exploit vulnerabilities passively. Their targets primarily included organizations in Europe, the Middle East, and recently expanded operations into the U.S. aviation sector.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline