An Iran-linked hacking group has been caught planting six new spying tools inside aerospace, defense and telecom companies, using fake recruiter messages to trick employees into opening malicious files. Palo Alto Networks' Unit 42 team, which tracks the group as Screening Serpens (also known as UNC1549, Smoke Sandstorm and "Iranian Dream Job"), says the break-ins ran from February through April 2026 and lined up closely with the regional conflict that began on February 28, 2026.
What's affected
According to Unit 42's report, malware samples point to victims in the United States, Israel and the United Arab Emirates, plus two more entities in the Middle East. The group has been active since at least 2022, long focused on the Middle East before pushing into Western Europe in late 2025. Its usual targets are aerospace, defense manufacturing and telecommunications firms, the kind of organizations that hold sensitive engineering and government work.
How the attack works
The attack starts with a spear-phishing message, a targeted email or chat built around a fake job offer that impersonates a trusted brand or hiring platform. When the victim opens the attached archive, the malware uses a trick called DLL sideloading, which slips malicious code into a legitimate program so it runs unnoticed. The six new trojans split into two families: a newly named one Unit 42 calls MiniUpdate, and an upgraded version called MiniJunk V2. Both give attackers remote access to the infected machine, letting them steal data and run further commands.
The standout twist is a technique called AppDomainManager hijacking. In plain terms, it abuses the startup process of .NET applications (a common Microsoft software framework) by feeding them a rigged configuration file. That file quietly switches off the application's own built-in security, leaving the computer wide open to the trojans. To stay hidden and dodge tracking, the operators route their command-and-control traffic, the channel they use to control infected machines, through three to five different web domains for each victim and each malware variant, most of them hosted on Microsoft Azure.
What you should do
Treat unexpected hiring outreach with caution, especially messages that arrive with an attached archive file. Security teams in aerospace, defense and telecommunications should flag such messages and watch for unusual .NET application configuration files appearing on their systems, a sign of the AppDomainManager trick. Unit 42 published indicators of compromise to help defenders hunt for this activity: a sample file with the MD5 fingerprint edcdba624ddb43c2a1dcf334aa493068, and a malicious staging link at hxxps://2117[.]filemail[.]com/api/file/get (defanged so it cannot be clicked by accident). Researchers also expect fake recruitment messages aimed at defense and technology staff to remain a favorite way in for Iran-linked hackers. Screening Serpens is not yet in the IntelFusions threat-actor catalog and is tracked here under Unit 42's naming for now.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.