Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Jul 28, 2026

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,

Get Free Report & Network Analysis

Please check your email for the free report.