Utopia Tech
SecurityAI-assisted1 min read

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Iranian state-backed threat actor Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, and others) has launched attacks across the Middle East, Africa, and South Asia using a newly discovered Windows backdoor called NightLedger. The campaign employs custom WebSocket tunnelers to transform compromised systems into covert relay infrastructure, demonstrating advanced persistence and evasion cap

UT

Utopia Tech

July 28, 2026 · 1 min read

Share

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content