An Iran-linked cyber-espionage group has expanded its operations beyond its traditional Middle Eastern hunting grounds to target critical infrastructure organizations across Western Europe using constantly improving malware variants and attack tactics. Researchers at Check Point Software are tracking the threat group as "Nimbus Manticore," which they said overlaps with UNC1549, or Smoke Sandstorm. "Each target receives a unique URL and credentials, enabling tracking and controlled access of each victim," Check Point said. In the background, the archive initiates what Check Point described as an elaborate process to download the malware on the victim system. "The execution chain leverages a unique technique which we call multi-stage sideloading," to install the malware and establish persistence, Check Point said.