---
title: "Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns"
url: https://daily.dev/posts/tracking-iranian-apt-screening-serpens-2026-espionage-campaigns-g1lvjgxxj
source_url: https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens
type: article
source: "Unit 42"
published: 2026-05-22T13:08:59.234Z
updated: 2026-05-22T13:09:26.112Z
tags: ["malware"]
reading_time: 27
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

**[Unit 42](https://daily.dev/sources/unit42)** · 27 min read · 0 upvotes · 0 comments

## Summary

Unit 42 researchers detail a series of cyberattack campaigns by the Iranian APT group Screening Serpens (UNC1549/Smoke Sandstorm) conducted between February and April 2026. The group deployed six new RAT variants across two malware families — MiniUpdate and MiniJunk V2 — targeting technology, defense, and aerospace entities in the U.S., Israel, UAE, and other Middle Eastern countries. A key technical evolution is the use of AppDomainManager hijacking, which manipulates .NET application initialization via legitimate configuration files to disable ETW telemetry, bypass strong-name signature validation, and suppress publisher policy redirections — effectively blinding EDR tools before the payload executes. Campaigns relied on highly tailored spear-phishing lures impersonating job portals, video conferencing platforms, and recruitment sites. The RATs support extensive capabilities including arbitrary command execution, DLL injection, file exfiltration with chunked uploads, UAC elevation, and scheduled task persistence.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens>

## Similar posts on daily.dev

- [SideWinder Espionage Campaign Expands Across Southeast Asia](https://daily.dev/posts/sidewinder-espionage-campaign-expands-across-southeast-asia-bdpa1s0qo) · Dark Reading · 0 upvotes · 0 comments
- [Iranian Hackers Launch 'SpearSpecter' Spy Operation on Defense & Government Targets](https://daily.dev/posts/iranian-hackers-launch-spearspecter-spy-operation-on-defense-government-targets-lbt7r1gbv) · The Hacker News · 1 upvotes · 0 comments
- [Iranian State APT Blitzes Telcos & Satellite Companies](https://daily.dev/posts/iranian-state-apt-blitzes-telcos-satellite-companies-ozqq4nm1i) · Dark Reading · 0 upvotes · 0 comments
- [Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit](https://daily.dev/posts/russian-threat-actor-sednit-resurfaces-with-sophisticated-toolkit-rnewjohnk) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/tracking-iranian-apt-screening-serpens-2026-espionage-campaigns-g1lvjgxxj)
