{"id":13129,"date":"2026-05-25T10:03:43","date_gmt":"2026-05-25T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/25\/miniupdate-rat-uses-azure-hosted-c2-domains-for-targeted-espionage-campaigns\/"},"modified":"2026-05-25T10:03:43","modified_gmt":"2026-05-25T10:03:43","slug":"miniupdate-rat-uses-azure-hosted-c2-domains-for-targeted-espionage-campaigns","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/25\/miniupdate-rat-uses-azure-hosted-c2-domains-for-targeted-espionage-campaigns\/","title":{"rendered":"MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns"},"content":{"rendered":"<p>    MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert. <\/p>\n<p class=\"wp-block-paragraph\">The threat comes from an Iran-linked hacking group deploying two families of remote access trojans through cleverly disguised recruitment lures and fake software installers. <\/p>\n<p class=\"wp-block-paragraph\">The campaign began as early as mid-February 2026 and continued expanding, with fresh samples appearing as recently as mid-April. Researchers believe the surge closely follows a Middle East regional conflict that started on February 28, 2026.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The group behind these intrusions is tracked as Screening Serpens, also known by the aliases UNC1549, Smoke Sandstorm, and Iranian Dream Job. <\/p>\n<p class=\"wp-block-paragraph\">It has been active since at least 2022 and historically focused on Middle Eastern targets before expanding into Western Europe in late 2025. Six newly discovered RAT variants have been grouped into two malware families: a new one called MiniUpdate, and an upgraded tool called MiniJunk V2. <\/p>\n<p class=\"wp-block-paragraph\">Analysts at Unit 42 identified these variants and assessed with moderate-high confidence that Screening Serpens is behind the operation.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/unit42.paloaltonetworks.com\/\" id=\"https:\/\/unit42.paloaltonetworks.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Unit 42\u00a0said in a report<\/a> shared with Cyber Security News (CSN) that both families are delivered through spear-phishing lures impersonating trusted brands and hiring platforms. <\/p>\n<p class=\"wp-block-paragraph\">Victims receive <a href=\"https:\/\/cybersecuritynews.com\/hackers-targeting-job-seekers\/\" id=\"78677\" target=\"_blank\" rel=\"noreferrer noopener\">fake job applications or spoofed meeting invitations<\/a> crafted to look completely genuine. Once a target opens the malicious archive and runs the included file, the infection chain quietly begins while the victim sees nothing unusual on screen.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-miniupdate-rat-uses-azure-hosted-c2-domains\" class=\"wp-block-heading\"><strong>MiniUpdate RAT Uses Azure-Hosted C2 Domains<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The MiniUpdate RAT is the more technically advanced of the two families and uses a technique called AppDomainManager hijacking. <\/p>\n<p class=\"wp-block-paragraph\">By altering a legitimate configuration file, the malware instructs the .NET runtime to disable its own security features before the host application fully loads. The result is a payload running in an environment where standard security monitoring tools are already blinded.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The configuration disables Event Tracing for Windows, a key telemetry source that security software uses to detect suspicious behavior, and also bypasses digital signature checks. <\/p>\n<p class=\"wp-block-paragraph\">The malware creates a scheduled task that fires daily at 09:30 local time, keeping it alive through system reboots. <a href=\"https:\/\/cybersecuritynews.com\/tools-for-conducting-malware-traffic-analysis-in-a-sandbox\/\" id=\"67491\" target=\"_blank\" rel=\"noreferrer noopener\">Command and control traffic routes through Azure-hosted domains<\/a> assigned to each specific target, preventing any single detection point from exposing the broader infrastructure.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj4V1fajyESmyYXbK00DQ5B7DkU-a0LGM0jBdweN_QeZT419shkr58usPfmWq8vyb6jzYe_2Z3pPdTI2emfN4xvI7pgDRxHJMtChpj1arhlbDiCr8Y5U7anVXuxG2js2kuq5pKURHgpBFYMuTJaCmZ3yos-9KjcU7q7dPx3zaGzoOulzgnyWAdo5b-jYXQ\/s16000\/Contents%2520of%2520the%2520archive%2520%28Source%2520-%2520Unit42%29.webp?ssl=1\" alt=\"Contents of the archive (Source - Unit42)\"><figcaption class=\"wp-element-caption\">Contents of the archive (Source \u2013 Unit42)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The March U.S. campaign delivered the RAT inside an archive disguised as airline recruitment materials, complete with fake job descriptions for senior technical roles. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgC_bGEKh2Mj_OgyXNTtkUS0Vu6-RJnW7iPC1yRxXGKoztY-9n3e4SgdjmWV_VygnK3ZM8UChEGJruYvY6WZosF6082vJCNvu722rGkNX3MWyVDiuop40uxRtAgsfABPjd8WVPpe8Q8xL2D3JUccvrGNMDAXoTD7NUqqOJ60ATp_vOdxW_1LEPqfFY8WBE\/s16000\/Spoofed%2520Hiring%2520Portal%2520error%2520window%2520%28Source%2520-%2520Unit42%29.webp?ssl=1\" alt=\"Spoofed Hiring Portal error window (Source - Unit42)\"><figcaption class=\"wp-element-caption\">Spoofed Hiring Portal error window (Source \u2013 Unit42)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The Israel campaign that same month used an archive <a href=\"https:\/\/cybersecuritynews.com\/microsoft-teams-request-remote-access\/\" id=\"121829\" target=\"_blank\" rel=\"noreferrer noopener\">impersonating a video conferencing installer<\/a>, with a spoofed loading screen shown to the user while the malware silently deployed behind the scenes.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 id=\"h-minijunk-v2-obfuscated-backdoor-targeting-tech-and-defense\" class=\"wp-block-heading\"><strong>MiniJunk V2: Obfuscated Backdoor Targeting Tech and Defense<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The MiniJunk V2 family, first spotted on February 17, 2026, takes a different approach to staying hidden. It inflates its file size to around 12 megabytes by embedding thousands of meaningless code strings from languages like Java and Python, pushing the file past the scanning limits of certain automated security tools. <\/p>\n<p class=\"wp-block-paragraph\">This also floods analysis software with irrelevant data, making manual investigation significantly harder.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">The malware uses two layers of DLL sideloading to deploy its payload and connects to five Azure-hosted command servers whose names are designed to resemble legitimate Windows service processes. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgnevIjZK4cdK45RKxwXf1Ozueja3T6T1qCTT0LWApRx3MOy_VqMhQ23kbdZIf4lcybO0uXvaHLHPCI3d2xdXIx3A4Gsr9sgM2wdBBDpWLArenY73WTCivs_NdK4lwtlxPO2pMCxNqu7dtOPEy7RcN-_uyg9WxUd4gL9MBeRxapPmTFAA_YSzVmS4z9lcs\/s16000\/MiniJunk%2520V2%2520malware%2520flow%2520%28Source%2520-%2520Unit42%29.webp?ssl=1\" alt=\"MiniJunk V2 malware flow (Source - Unit42)\"><figcaption class=\"wp-element-caption\">MiniJunk V2 malware flow (Source \u2013 Unit42)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">The March U.S. variant includes a hard-coded date check that prevents the RAT from activating before March 27, 2026, at 13:30 UTC, making early sandbox analysis nearly useless. <\/p>\n<p class=\"wp-block-paragraph\">A fake \u201cMeeting Room\u201d window is shown to the victim to keep attention away from what is running in the background.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\">Security teams are advised to <a href=\"https:\/\/cybersecuritynews.com\/onedrive-exe-dll-sideloading-with-malicious-dll-files\/\" id=\"132304\" target=\"_blank\" rel=\"noreferrer noopener\">configure endpoint detection tools to flag DLL sideloading<\/a> and AppDomainManager hijacking as high-risk behaviors, rather than relying solely on known file signatures. <\/p>\n<p class=\"wp-block-paragraph\">Monitoring for trusted binaries that load unsigned or unrecognized modules adds an important detection layer against this type of attack. <\/p>\n<p class=\"wp-block-paragraph\">Organizations in aerospace, defense, telecommunications, and technology should treat unsolicited job-related archives or unexpected software update prompts with strong suspicion, as these remain the group\u2019s preferred entry points.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/3c52aca4-714e-4016-b9af-4298844bb4a5\/MiniUpdate-RAT-Uses-Azure-Hosted-C2-Domains-for-Targeted-Espionage-Campaigns.pdf?AWSAccessKeyId=ASIA2F3EMEYE4X6J5SBY&amp;Signature=04KOOBKNdQf1XJ3Q9fRi7bqwvro%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQD3tmz8XNsQwcRWeYKfqk09celP3WkIFVrNECoKBKGZkAIhAKNE8FBQx4ggQlSRiuvdzTG0dnx2Q6ppfEkBycp95HQAKvMECGAQARoMNjk5NzUzMzA5NzA1IgxoAVXO7qmdWmsy0F4q0ATUFh7uHfKbSnAhorysw6yDvdNhdDHog9E%2FVynD%2FhYdenT6gwFZ0np7l%2Fy%2FbM1bzU3Wgc9RCY%2BaZVx6F6x9XTOgBxWfdD0nTVJKhdq4UrdXK72PQcBCVcLcvj7OMfR1nVxcbYF4VttXz9oQ865Hb8%2BDx7vTzO3qBfBQcdLPP%2FLPK91yP%2BygPJc4sFztD0MN91ADT%2BkleQrqhwn13%2BY1DO%2FT09AxThrnqBSlIzkEsOvzjHA%2BWgwD0fgF0IN0D4BJokpDnC1iduQhJPbNrf1ukw5e9wVQ%2BCRkZFIZM8DwdxSwCajFl6yfv4Bx2cYxpKZ0WmZ9Hylxs2L%2FE4qx7ftkIquwuBUZm9N5ugI4khzOGss%2BiKvAljwHWLl6PDmpcuogtE1PrZTyJJkOMxiv81RkrapsFKeSNQgtf4fhVtiHDr94zLS%2FYtK51nnh2fRBlCQFSfw1cUgg0aMDN7PAeHSh2HM418f9ObzcGXaky6dUXNRL7bFTNZL1w%2Bd2Utta0BCzAYBuiAbqCU6Tw71FH5TjLE7xoOr52qHvrMSNjZTLe%2BdwTHrkfIJI5SVE0aK3ohOy%2BaOvdlCfjxgRzBCfxgqaEm355V6Kvgio1F%2BMNwKmVnTGNTXdDLR5Vz09mvtL1ykbug7ERZ0Gx97jekM3yQhPTZm7xuDKakOUJOeFLnyiQzAWfKf2BcleNwSeUNHmL2DBWCwiRHDRrfdm6qkzDZexQETrgaINp%2Bxzeihgc%2FEktnpSgprd%2BPb08EDbWG7CG7bbyKBsv4sMM6wXpWPHpZe4HbUhMOHiz9AGOpcBKp2iQkevrjJBnABYfKwHWJan1FUXz7E3xsc43vg3QZts4EtOe23UpdTYYrikJevRiP3sBQuGupLLAUu%2F%2FKzY3g61zPTC%2FZv6OZT0QCelqFk3Pb5pxj25TAzwa1yx83%2FS8DnJHi9lC280K9gqimj2oKRMR5K%2BqtCh4S%2B3aSfyY0JXnv2R4FOBq%2BMjM6MZltuZ55vAbbjVDg%3D%3D&amp;Expires=1779693431\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"wp-block-paragraph\" id=\"h-indicators-of-compromise-iocs\"><strong>Indicators of Compromise (IoCs):-<\/strong><\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Indicator<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Domain<\/td>\n<td>licencemanagers.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>LicenceSupporting.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>PeerDistSvcManagers.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>ThemesManagers.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>ThemesProviderManagers.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>NanoMatrix.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 US Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>QuantumWeave.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 US Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>ElementShift.azurewebsites[.]net<\/td>\n<td>MiniJunk V2 US Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>buisness-centeral.azurewebsites[.]net<\/td>\n<td>MiniUpdate C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>buisness-centeral-transportation.azurewebsites[.]net<\/td>\n<td>MiniUpdate C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>Buisness-centeral-transportation[.]com<\/td>\n<td>MiniUpdate C2 domain<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>PremierHealthAdvisory[.]com<\/td>\n<td>MiniUpdate UAE Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>PremierHealthAdvisory.azurewebsites[.]net<\/td>\n<td>MiniUpdate UAE Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>Premier-HealthAdvisory.azurewebsites[.]net<\/td>\n<td>MiniUpdate UAE Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>Ramiltonsfinance[.]com<\/td>\n<td>MiniUpdate Middle East Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>Ramiltonsfinance.azurewebsites[.]net<\/td>\n<td>MiniUpdate Middle East Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>Ramiltons-finance.azurewebsites[.]net<\/td>\n<td>MiniUpdate Middle East Campaign C2<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>business-startup[.]org<\/td>\n<td>Screening Serpens infrastructure<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>business-startup.azurewebsites[.]net<\/td>\n<td>Screening Serpens infrastructure<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>docspace-y4cumb.onlyoffice[.]com<\/td>\n<td>Payload delivery host (ONLYOFFICE)<\/td>\n<\/tr>\n<tr>\n<td>Domain<\/td>\n<td>docspace-twpf0e.onlyoffice[.]com<\/td>\n<td>Payload delivery host (ONLYOFFICE)<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>hxxps[:]\/\/docspace-y4cumb.onlyoffice[.]com\/storage\/files\/root\/folder_3602000\/file_3601577\/v1\/content.zip<\/td>\n<td>MiniJunk V2 payload delivery URL<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>hxxps[:]\/\/docspace-twpf0e.onlyoffice[.]com\/storage\/files\/root\/folder_3765000\/file_3764519\/v1\/content.zip<\/td>\n<td>MiniJunk V2 US campaign delivery URL<\/td>\n<\/tr>\n<tr>\n<td>URL<\/td>\n<td>hxxps[:]\/\/2117.filemail[.]com\/api\/file\/get?filekey=T0EnWQ6NugHkW_kLfDxPBEw_um6NSkg9ZwNRQ_5lrKrLLUo35pV8m3TKv1LqF3zZzdUm<\/td>\n<td>MiniUpdate Israel campaign payload URL<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>44f4f7aca7f1d9bfdaf7b3736934cbe19f851a707662f8f0b0c49b383e054250<\/td>\n<td>MiniUpdate US campaign \u2013 initial archive<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>332ba2f0297dfb1599adecc3e9067893e7cf243aa23aedce4906a4c480574c17<\/td>\n<td>MiniUpdate US campaign \u2013 Hiring Portal.zip<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864<\/td>\n<td>MiniUpdate US campaign \u2013 UpdateChecker.dll<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>38bd137c672bd58d08c4f0502f993a6561e2c3411773d1ae57ee0151a0a9d11d<\/td>\n<td>MiniUpdate Israel campaign \u2013 initial archive<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>d4a7e9f107fe40c1a5d0139c6c6e25bf6bf57f61feff090bee28f476bb3cc3c2<\/td>\n<td>MiniUpdate Israel campaign \u2013 UpdateChecker.dll<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>bc3b44154518c5794ce639108e7b9c5fecb0c189607a26de1aaed518d890c7ad<\/td>\n<td>MiniUpdate UAE\/Middle East \u2013 UpdateChecker.dll<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>74882085db2088356ed7f72f01e0404a0a98cda88ef56fb15ce74c1f36b26d27<\/td>\n<td>MiniUpdate Middle East campaign<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>9cf029daca89523d917dafed0568d11d00e45ec96b5b90b4a1f7fd4018c7da84<\/td>\n<td>MiniJunk V2 Middle East \u2013 uevmonitor.dll<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>b19e06da580cf91691eda066ac9ee4b09c6e5dc26c367af12660fe1f9306eec4<\/td>\n<td>MiniJunk V2 Middle East \u2013 unbcl.dll<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>8808c794c24367438f183e4be941876f1d3ecd0c8d2eb43b10d2380841d2283b<\/td>\n<td>MiniJunk V2 US campaign \u2013 Portable Platform.zip<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>43dc62cef52ebdd69e79f10015b3e13890f26c058325c0ff139c70f8d8eadcfa<\/td>\n<td>MiniJunk V2 US campaign \u2013 Connection.dll<\/td>\n<\/tr>\n<tr>\n<td>SHA256<\/td>\n<td>9e4a658e6d831c9e9bdfe11884a75b7c64812ed0a80e8495ddf6b316505acac1<\/td>\n<td>MiniJunk V2 US campaign \u2013 unbcl.dll<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>UpdateChecker.dll<\/td>\n<td>MiniUpdate RAT core payload<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>uevmonitor.dll<\/td>\n<td>MiniJunk V2 primary loader DLL<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>Connection.dll<\/td>\n<td>MiniJunk V2 US campaign RAT payload<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>Hiring Portal.zip<\/td>\n<td>Lure archive used in US\/Israel campaigns<\/td>\n<\/tr>\n<tr>\n<td>File Name<\/td>\n<td>Portable platform.zip<\/td>\n<td>Lure archive used in US MiniJunk V2 campaign<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong>\u00a0<em>IP addresses and domains are intentionally defanged (e.g.,\u00a0<\/em><code><em>[.]<\/em><\/code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM<\/em>.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/miniupdate-rat-uses-azure-hosted-c2-domains\/\">MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/miniupdate-rat-uses-azure-hosted-c2-domains\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert. The threat comes from an Iran-linked hacking group deploying two families of remote access trojans through cleverly disguised recruitment lures and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-13129","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13129"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=13129"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/13129\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=13129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=13129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=13129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}