Iranian State-Backed Group Nimbus Manticore Utilizes NightLedger Backdoor and Tunneling Tools in Cyber Espionage Campaign
Iranian state-backed group Nimbus Manticore employs NightLedger, a new Windows backdoor, and custom WebSocket tunnelers to maintain covert access in targeted Middle Eastern, African, and South Asian entities. The campaign uses phishing lures and DLL side-loading for initial access, with tunneling tools enabling operator-controlled network relays.
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,
*** END OF TRANSMISSION ***