ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Nimbus Manticore backdoor NightLedger and WebSocket tunneling toolset

Source headline: Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

Nimbus Manticore, an Iranian state-backed intrusion set, is linked to new compromises affecting organizations across the Middle East, Africa, and South Asia. The campaign uses a previously undocumented Windows backdoor dubbed NightLedger. It also relies on two custom WebSocket tunnelers to move and relay traffic covertly through victim environments. Once installed, compromised systems can function as covert relays for attacker communications. Organizations should review for suspicious NightLedger activity and restrict or monitor outbound WebSocket connections.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#command-and-control #iranian #nightledger #state-backed #websocket #windows-backdoor
Original reporting The Hacker News Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Open original source