HackerFeeds

CyberSecurity News

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The Hacker News
· July 28, 2026

AI summary

Nimbus Manticore, an Iranian state-backed hacking group, has been linked to a new series of attacks targeting organizations in the Middle East, Africa, and South Asia. The group is using a previously undocumented Windows backdoor called NightLedger, along with custom WebSocket tunnelers, to carry out the intrusions. These attacks enable the group to turn compromised systems into covert relays. The hacking group is also known by several other names, including GalaxyGato and UNC1549. The use of NightLedger and the WebSocket tunnelers allows Nimbus Manticore to maintain access to victim systems. The group's activities have been detected across multiple regions.

Read the full article at The Hacker Newsthehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.