language
Detectat automat

Am preselectat Română și Romanian Leu (lei) pentru tine.

Autentificare
softwarebay.de
softwarebay.de
Nimbus Manticore Utilizes NightLedger for Cyber Attacks
News Cybersecurity Nimbus Manticore Utilizes NightLedger for Cyber At...
Cybersecurity

Nimbus Manticore Utilizes NightLedger for Cyber Attacks

Nimbus Manticore Utilizes NightLedger for Cyber Attacks

The Iranian state-sponsored hacker group Nimbus Manticore, also known by the names GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, has conducted a series of new cyber attacks. These attacks target various organizations in the regions of the Middle East, Africa, and South Asia. The group is utilizing a previously undocumented Windows backdoor named NightLedger. The attacks involve the use of two custom WebSocket tunnellers that allow the attackers to infiltrate the victims' networks undetected. This technique is commonly used to exfiltrate data or to install additional malware.

The exact functionality of NightLedger and the tunnellers is not yet fully understood; however, initial analyses suggest a high level of complexity. The security firm investigating the attacks reports that the attacks occurred in multiple waves and spanned several months. The first indications of Nimbus Manticore's activities were discovered in the first quarter of 2026. The group has made a name for itself in the past through targeted attacks on critical infrastructure and government entities. A notable feature of the attacks is NightLedger's ability to convert victim systems into covert relays.

This enables the attackers to obfuscate their activities and evade monitoring by security authorities. The use of such techniques indicates the advanced capabilities of the group and their strategic focus. The affected organizations primarily operate in the energy, telecommunications, and government services sectors. Experts warn that the attacks not only target immediate objectives but could also have far-reaching implications for the national security of the affected countries. Security authorities in the impacted regions have already taken measures to investigate the attacks and secure the systems.

The discovery of NightLedger and the associated WebSocket tunnellers has drawn the attention of the cybersecurity community. Researchers are working to analyze the background of the malware and develop potential countermeasures. The complexity of the attacks suggests that Nimbus Manticore possesses significant resources and technical expertise. The Iranian government has not yet commented on the allegations. However, experts suspect that the attacks are part of a larger strategy for intelligence gathering and destabilization in the region.

Activities by Nimbus Manticore could also be interpreted as a response to the geopolitical tensions that have increased in recent years. The vulnerability exploited by NightLedger is currently not publicly documented. Experts advise organizations to regularly update their systems and review security protocols to defend against such attacks. The exact number of affected systems remains unclear, but a significant number of compromises is anticipated.

The cybersecurity firm analyzing the attacks plans to release detailed technical reports in the coming weeks. These reports are expected to provide further information on the functionality of NightLedger and the WebSocket tunnellers. The publication is anticipated for August 15, 2026.

Tags: Cybersecurity Nimbus Manticore NightLedger Iran Malware WebSocket

💬 Comentarii (0)

Scrie un comentariu

info Va fi publicat dupa moderare
chat_bubble_outline

Inca nu exista comentarii. Fii primul!

Live support available
Sarah E.
Sarah E.
check_circle Bucharest
Hello! I am Sarah. Do you have questions about our products or need help?
chat_bubble