← Back to Feed

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

July 28, 2026 · The Hacker News · Severity: MEDIUM

Iranian state-backed group Nimbus Manticore (aka GalaxyGato, Smoke Sandstorm, UNC1549) targeted entities across the Middle East, Africa, and South Asia using a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers (BridgeHead and ArcBridge). Targets included government, aviation, telecom, and financial organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso.

Key Takeaways

  • Iranian APT group Nimbus Manticore attributed to fresh attacks using the NightLedger Windows backdoor
  • NightLedger provides reconnaissance, command execution, file operations, process discovery, and screenshot capture
  • Two custom WebSocket tunnelers — ArcBridge and BridgeHead — provide covert network access and tunneling
☕ Buy a Coffee