Skip to content

Malware

MiniFast

According to Check Point Research, "MiniFast" is a 64-bit Windows DLL backdoor that appears to be under active development and shows multiple signs of AI-assisted coding, including verbose error handl

MiniFast is a Windows malware family operated by UNC1549.

Background

Check Point Research characterizes "MiniFast" as a 64-bit Windows DLL backdoor that still seems to be in active development and bears several hallmarks of AI-assisted coding, such as wordy error handling, a modular layout, and descriptive function names. Built for sustained access and remote management, it relies on a structured command-and-control protocol covering host registration, task polling, and result reporting. The backdoor carries out simple system reconnaissance and offers an extensive set of post-compromise operations, among them file and directory handling, command execution, listing and killing processes, file transfer, archive creation, and on-the-fly loading of extra code modules. It can also adjust its check-in cadence on operator command and runs tasks through an opcode-driven command framework. Before activating, MiniFast validates its execution chain and runs anti-analysis checks to confirm it is in an expected environment. Operators typically deliver it via multi-stage infection chains that misuse legitimate .NET application behavior and trusted execution paths to blend into normal activity and gain persistence.


Source: Malpedia (Fraunhofer FKIE).