diff --git a/iocs/c2-iocs.txt b/iocs/c2-iocs.txt index 072c501b..4429cd9a 100644 --- a/iocs/c2-iocs.txt +++ b/iocs/c2-iocs.txt @@ -1912,4 +1912,18 @@ repocket.com env-check.daemontools.cc 38.180.107.76 +# Nimbus Manticore (UNC1549) APT Backdoor 2026-05-26 (MAL, APT) +globalitconsultants.azurewebsites.net +globalbusiness-checkers-it.azurewebsites.net +global-check-business-it.azurewebsites.net +global-check-itbusiness.azurewebsites.net +global-it-checkbusiness.azurewebsites.net +global-it-consultants.azurewebsites.net +globalit-consultants.azurewebsites.net +global-it-checkers.azurewebsites.net +business-dns-ns-joiners.azurewebsites.net +ebix-exam-join-from-app.azurewebsites.net +business-joiners-exam.azurewebsiets.net +join-exam-now-ebix.azurewebsites.net + # Last Line diff --git a/iocs/filename-iocs.txt b/iocs/filename-iocs.txt index 0bcf1ade..1048d16b 100644 --- a/iocs/filename-iocs.txt +++ b/iocs/filename-iocs.txt @@ -4577,4 +4577,10 @@ C:\\Windows\\Temp\\imp\.tmp;85 C:\\Windows\\Temp\\piyu\.exe;85 C:\\ProgramData\\Microsoft\\mcrypto\.chiper;85 +# Nimbus Manticore APT Backdoor (UNC1549) 2026-05-26 (MAL, APT) +\\AppData\\Local\\VirtualStore\\result\.con;85 +\\CKAConsent\.dll;85 +\\2FAGuard\\main\.dll;85 +\\2FAGuard\\setup\.exe\.config;85 + # End diff --git a/yara/apt_apt35_malware_may26.yar b/yara/apt_apt35_malware_may26.yar new file mode 100644 index 00000000..63dd001b --- /dev/null +++ b/yara/apt_apt35_malware_may26.yar @@ -0,0 +1,83 @@ +rule SUSP_ScheduledTasks_Nimbus_Manticore_Persistence_May26 { + meta: + description = "Detects scheduled task used for persistence by Nimbus Manticore (UNC1549). The task is used to persistenly load a custom implant that features data exfiltration and remote control capabilities." + author = "Jonathan Peters (Nextron Systems)" + date = "2026-05-27" + reference = "https://www.nextron-systems.com/2026/06/01/detecting-nimbus-manticore-and-their-sideloading-infection-chains/" + score = 75 + strings: + $a0 = "