CyberSecurity News
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
AI summary
Nimbus Manticore, an Iranian state-backed hacking group, has been linked to a new series of attacks targeting organizations in the Middle East, Africa, and South Asia. The group is using a previously undocumented Windows backdoor called NightLedger, along with custom WebSocket tunnelers, to carry out the intrusions. These attacks enable the group to turn compromised systems into covert relays. The hacking group is also known by several other names, including GalaxyGato and UNC1549. The use of NightLedger and the WebSocket tunnelers allows Nimbus Manticore to maintain access to victim systems. The group's activities have been detected across multiple regions.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

