Skip to content
Malware

MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns

A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert. The threat comes from an Iran-linked hacking group deploying two families of remote access trojans through cleverly disguised recruitment lures and...

· May 27, 2026 · 6 min read · 👁 2 views
MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns

A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert.

The threat comes from an Iran-linked hacking group deploying two families of remote access trojans through cleverly disguised recruitment lures and fake software installers.

The campaign began as early as mid-February 2026 and continued expanding, with fresh samples appearing as recently as mid-April. Researchers believe the surge closely follows a Middle East regional conflict that started on February 28, 2026.

The group behind these intrusions is tracked as Screening Serpens, also known by the aliases UNC1549, Smoke Sandstorm, and Iranian Dream Job.

It has been active since at least 2022 and historically focused on Middle Eastern targets before expanding into Western Europe in late 2025. Six newly discovered RAT variants have been grouped into two malware families: a new one called MiniUpdate, and an upgraded tool called MiniJunk V2.

Analysts at Unit 42 identified these variants and assessed with moderate-high confidence that Screening Serpens is behind the operation.

Unit 42 said in a report shared with Cyber Security News (CSN) that both families are delivered through spear-phishing lures impersonating trusted brands and hiring platforms.

Victims receive fake job applications or spoofed meeting invitations crafted to look completely genuine. Once a target opens the malicious archive and runs the included file, the infection chain quietly begins while the victim sees nothing unusual on screen.

MiniUpdate RAT Uses Azure-Hosted C2 Domains

The MiniUpdate RAT is the more technically advanced of the two families and uses a technique called AppDomainManager hijacking.

By altering a legitimate configuration file, the malware instructs the .NET runtime to disable its own security features before the host application fully loads. The result is a payload running in an environment where standard security monitoring tools are already blinded.

The configuration disables Event Tracing for Windows, a key telemetry source that security software uses to detect suspicious behavior, and also bypasses digital signature checks.

The malware creates a scheduled task that fires daily at 09:30 local time, keeping it alive through system reboots. Command and control traffic routes through Azure-hosted domains assigned to each specific target, preventing any single detection point from exposing the broader infrastructure.

Contents of the archive (Source - Unit42)
Contents of the archive (Source – Unit42)

The March U.S. campaign delivered the RAT inside an archive disguised as airline recruitment materials, complete with fake job descriptions for senior technical roles.

Spoofed Hiring Portal error window (Source - Unit42)
Spoofed Hiring Portal error window (Source – Unit42)

The Israel campaign that same month used an archive impersonating a video conferencing installer, with a spoofed loading screen shown to the user while the malware silently deployed behind the scenes.

MiniJunk V2: Obfuscated Backdoor Targeting Tech and Defense

The MiniJunk V2 family, first spotted on February 17, 2026, takes a different approach to staying hidden. It inflates its file size to around 12 megabytes by embedding thousands of meaningless code strings from languages like Java and Python, pushing the file past the scanning limits of certain automated security tools.

This also floods analysis software with irrelevant data, making manual investigation significantly harder.

The malware uses two layers of DLL sideloading to deploy its payload and connects to five Azure-hosted command servers whose names are designed to resemble legitimate Windows service processes.

MiniJunk V2 malware flow (Source - Unit42)
MiniJunk V2 malware flow (Source – Unit42)

The March U.S. variant includes a hard-coded date check that prevents the RAT from activating before March 27, 2026, at 13:30 UTC, making early sandbox analysis nearly useless.

A fake “Meeting Room” window is shown to the victim to keep attention away from what is running in the background.

Security teams are advised to configure endpoint detection tools to flag DLL sideloading and AppDomainManager hijacking as high-risk behaviors, rather than relying solely on known file signatures.

Monitoring for trusted binaries that load unsigned or unrecognized modules adds an important detection layer against this type of attack.

Organizations in aerospace, defense, telecommunications, and technology should treat unsolicited job-related archives or unexpected software update prompts with strong suspicion, as these remain the group’s preferred entry points.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainlicencemanagers.azurewebsites[.]netMiniJunk V2 C2 domain
DomainLicenceSupporting.azurewebsites[.]netMiniJunk V2 C2 domain
DomainPeerDistSvcManagers.azurewebsites[.]netMiniJunk V2 C2 domain
DomainThemesManagers.azurewebsites[.]netMiniJunk V2 C2 domain
DomainThemesProviderManagers.azurewebsites[.]netMiniJunk V2 C2 domain
DomainNanoMatrix.azurewebsites[.]netMiniJunk V2 US Campaign C2
DomainQuantumWeave.azurewebsites[.]netMiniJunk V2 US Campaign C2
DomainElementShift.azurewebsites[.]netMiniJunk V2 US Campaign C2
Domainbuisness-centeral.azurewebsites[.]netMiniUpdate C2 domain
Domainbuisness-centeral-transportation.azurewebsites[.]netMiniUpdate C2 domain
DomainBuisness-centeral-transportation[.]comMiniUpdate C2 domain
DomainPremierHealthAdvisory[.]comMiniUpdate UAE Campaign C2
DomainPremierHealthAdvisory.azurewebsites[.]netMiniUpdate UAE Campaign C2
DomainPremier-HealthAdvisory.azurewebsites[.]netMiniUpdate UAE Campaign C2
DomainRamiltonsfinance[.]comMiniUpdate Middle East Campaign C2
DomainRamiltonsfinance.azurewebsites[.]netMiniUpdate Middle East Campaign C2
DomainRamiltons-finance.azurewebsites[.]netMiniUpdate Middle East Campaign C2
Domainbusiness-startup[.]orgScreening Serpens infrastructure
Domainbusiness-startup.azurewebsites[.]netScreening Serpens infrastructure
Domaindocspace-y4cumb.onlyoffice[.]comPayload delivery host (ONLYOFFICE)
Domaindocspace-twpf0e.onlyoffice[.]comPayload delivery host (ONLYOFFICE)
URLhxxps[:]//docspace-y4cumb.onlyoffice[.]com/storage/files/root/folder_3602000/file_3601577/v1/content.zipMiniJunk V2 payload delivery URL
URLhxxps[:]//docspace-twpf0e.onlyoffice[.]com/storage/files/root/folder_3765000/file_3764519/v1/content.zipMiniJunk V2 US campaign delivery URL
URLhxxps[:]//2117.filemail[.]com/api/file/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUmMiniUpdate Israel campaign payload URL
SHA25644f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250MiniUpdate US campaign – initial archive
SHA256332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17MiniUpdate US campaign – Hiring Portal.zip
SHA2560db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864MiniUpdate US campaign – UpdateChecker.dll
SHA25638bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11dMiniUpdate Israel campaign – initial archive
SHA256d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2MiniUpdate Israel campaign – UpdateChecker.dll
SHA256bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7adMiniUpdate UAE/Middle East – UpdateChecker.dll
SHA25674882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27MiniUpdate Middle East campaign
SHA2569cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84MiniJunk V2 Middle East – uevmonitor.dll
SHA256b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4MiniJunk V2 Middle East – unbcl.dll
SHA2568808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283bMiniJunk V2 US campaign – Portable Platform.zip
SHA25643dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfaMiniJunk V2 US campaign – Connection.dll
SHA2569e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1MiniJunk V2 US campaign – unbcl.dll
File NameUpdateChecker.dllMiniUpdate RAT core payload
File Nameuevmonitor.dllMiniJunk V2 primary loader DLL
File NameConnection.dllMiniJunk V2 US campaign RAT payload
File NameHiring Portal.zipLure archive used in US/Israel campaigns
File NamePortable platform.zipLure archive used in US MiniJunk V2 campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you