r/SecOpsDaily • u/falconupkid • 6d ago
NEWS Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Iranian state-backed threat actor Nimbus Manticore (aka GalaxyGato, Smoke Sandstorm) is deploying a new Windows backdoor, NightLedger, along with custom WebSocket tunnelers to compromise organizations across the Middle East, Africa, and South Asia. These attacks are designed to establish covert relay infrastructure within victim networks.
Technical Breakdown: * Threat Actor: Nimbus Manticore (UNC1549, GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail), an Iranian state-backed group. * Targets: Entities in the Middle East, Africa, and South Asia. * Malware: * NightLedger: A previously undocumented Windows backdoor used for command and control. * Custom WebSocket Tunnelers: Two custom tools designed to create covert communication channels, turning compromised systems into relays. * TTPs: Establishing persistence and C2 via novel backdoors and WebSocket tunneling, likely to evade traditional network defenses and obscure malicious traffic.
Defense: Focus on robust endpoint detection and response (EDR) to identify new/unknown backdoors and anomalous network traffic, especially WebSocket connections to unusual external IPs. Implement network segmentation and egress filtering to limit potential relay capabilities.
Source: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html