Cyber campaigns linked to Iran expand with AI and SEO poisoning tactics

Cyberattack campaigns linked to Iranian groups are increasingly incorporating new malware distribution tactics and AI-assisted tools.
A report from Check Point Research warns of operations targeting aviation, software and developer sectors across the United States, Europe and the Middle East.
Check Point Research (CPR) published a new report detailing activities attributed to Nimbus Manticore, a cybercriminal group linked to Iran’s Islamic Revolutionary Guard Corps (IRGC).
According to the investigation, the group deployed new malicious campaigns targeting organizations in the aviation and software sectors across the United States, Europe and the Middle East.
Researchers identified the use of fake job offers and fraudulent download websites designed to distribute malware.
Researchers detect AI-assisted malware development.
One of the report’s main findings involves the alleged use of artificial intelligence tools and large language models (LLMs) to accelerate malware development and deployment during the conflict.
According to Check Point Research, the analyzed code displayed characteristics consistent with AI-assisted generation, including unusual modular structures, excessive error handling and overly long function names.
The cybersecurity firm indicated that these tools could allow cybercriminal groups to develop new malicious capabilities more rapidly while maintaining operations under geopolitical and military pressure.
Campaign also used SEO manipulation to distribute malware.
Researchers also identified the use of SEO manipulation techniques to distribute malware, a tactic that Check Point Research said it had observed for the first time in operations attributed to Nimbus Manticore.
According to the report, the group created a fake download page for SQL Developer software and managed to position it among the top search results on Bing and DuckDuckGo.
The investigation warns that this strategy expands the potential reach of attacks beyond traditional spearphishing campaigns by exposing developers and ordinary users searching for legitimate software.
Check Point Research also stated that the identified operations were not part of a single isolated campaign.
The company tracked three separate waves between February and April, including phases before the conflict, operations during active hostilities and activity following the ceasefire.
According to specialists, this suggests the group maintained operational continuity throughout the analyzed period while diversifying attack tactics alongside geopolitical tensions.
Sergey Shykevich, Threat Intelligence Group Manager at Check Point Research, noted:
“What stands out is that this group’s ambitions extended far beyond targeted espionage in the Middle East. We found strong indications that Nimbus Manticore used AI tools to develop malware more quickly. We also tracked a third campaign wave using a completely different strategy: SEO poisoning.”
According to specialists, the case reflects how cybercriminal groups are beginning to combine artificial intelligence, phishing campaigns and search engine manipulation to expand both the reach and sophistication of malicious operations.

