Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Summary
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.