Public Event Detail
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
Public historical observation from the Merrowstone archive. This page shows event-level context only. Accepted assertions, evidence lineage, and relationship intelligence remain part of the premium research layer.
Event summary
Unit 42 researchers have observed an increase in cyberattacks by the Iranian APT group, Screening Serpens (also known as UNC1549, Smoke Sandstorm, and Iranian Dream Job), targeting entities in the U.S., Israel, UAE, and two other Middle Eastern countries. These campaigns, coinciding with a regional conflict starting in February 2026, demonstrate the group's enhanced technical capabilities and operational resilience, including the deployment of six new remote access Trojan (RAT) variants from two new malware families, MiniUpdate and MiniJunk V2. A critical evolution in their recent campaign involves AppDomainManager hijacking to disable application security mechanisms, emphasizing the need for robust EDR tools tuned to detect DLL sideloading and AppDomainManager hijacking.