ShellCodeX Intelligence Brief
HIGH
Cybersecurity
Nimbus Manticore backdoor NightLedger and WebSocket tunneling toolset
Source headline: Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
3 hours ago
Intelligence Summary
Nimbus Manticore, an Iranian state-backed intrusion set, is linked to new compromises affecting organizations across the Middle East, Africa, and South Asia. The campaign uses a previously undocumented Windows backdoor dubbed NightLedger. It also relies on two custom WebSocket tunnelers to move and relay traffic covertly through victim environments. Once installed, compromised systems can function as covert relays for attacker communications. Organizations should review for suspicious NightLedger activity and restrict or monitor outbound WebSocket connections.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Open original source