:

IRAN-LINKED GROUP USES AI MALWARE IN CYBER ATTACKS

AI DESK2 MIN READ
MON, MAY 25, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Iranian threat actor Nimbus Manticore has resurfaced using AI-assisted malware development and SEO poisoning techniques to target companies, according to Check Point Research. The IRGC-affiliated group escalated operations during recent US-Iran tensions.

Check Point Research identified Nimbus Manticore, an Iranian threat actor with ties to the Islamic Revolutionary Guard Corps (IRGC), employing advanced techniques in recent cyber campaigns. The group leveraged artificial intelligence to develop malware and deployed SEO poisoning strategies to compromise target organizations. Attack Methods The threat actor combined multiple techniques to maximize impact. AI-assisted malware development allowed attackers to create variants faster and potentially evade traditional detection methods. Simultaneously, SEO poisoning—manipulating search results to direct users to malicious sites—served as an initial infection vector, exploiting legitimate search traffic. Operational Context Nimbus Manticore's resurgence coincided with Operation Epic Fury, reflecting heightened cyber activity during escalating US-Iran tensions. The timing suggests coordinated campaigns aligned with geopolitical developments. Implications The integration of AI tools into malware development marks an evolution in Iranian cyber capabilities. Rather than relying solely on manual coding, threat actors can now automate and accelerate payload creation, making detection and attribution more difficult. SEO poisoning extends the attack surface beyond traditional enterprise defenses, targeting users before they reach corporate networks. The group's targeting of companies indicates interest in both espionage and operational impact. Organizations face dual threats: technical malware infections and social engineering through poisoned search results. Defense Recommendations Security teams should implement robust email filtering, endpoint detection systems tuned for AI-generated malware variants, and user awareness training on search result verification. Organizations should also monitor for indicators of compromise associated with Nimbus Manticore campaigns and consider threat intelligence sharing with industry peers. Check Point Research continues monitoring the threat actor's infrastructure and tactics as operations develop.

■ SOURCES

Techmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.

JUST NOWAI Desk

Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.

JUST NOWSecurity Desk

Security research firms METR and Redwood have published a detailed postmortem examining the HuggingFace security incident. The analysis provides technical insights into how the breach occurred and what systems were compromised.

5H AGOSecurity Desk

More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.

5H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.