Nimbus Manticore, an Iranian state-sponsored hacking group, has been linked to a series of recent cyberattacks targeting organizations in the Middle East, Africa, and South Asia. The group has introduced a previously undocumented Windows backdoor named NightLedger, alongside two custom WebSocket tunnelers, to facilitate their operations. This marks a notable shift in their tactics, indicating a focus on stealth and persistence in infiltrating victim systems, turning them into covert relays for further attacks.
For businesses operating in or connected to these regions, this development underscores the need for heightened vigilance and advanced security measures to protect against sophisticated infiltration techniques. The use of NightLedger represents a significant evolution in the threat landscape, emphasizing the importance of proactive cybersecurity strategies and incident response planning. As cyber threats continue to evolve, particularly from state-sponsored actors, organizations must prioritize the implementation of robust defense mechanisms and continuous monitoring to mitigate potential risks associated with such advanced persistent threats.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html)*