Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Nimbus Manticore Targets Critical Sectors with New Malware

Nimbus Manticore Targets Critical Sectors with New Malware

Posted on July 28, 2026 By CWS

An Iranian state-sponsored hacking group known as Nimbus Manticore has been linked to a recent series of cyberattacks on organizations in the Middle East, Africa, and South Asia. Utilizing a newly discovered Windows backdoor called NightLedger, the group aims to maintain clandestine access to affected systems.

Targeted Regions and Sectors

The attacks have impacted a variety of sectors, including governments and small-to-medium businesses in Jordan and Tanzania, aviation firms in Pakistan, telecommunications in Ethiopia, and financial institutions in Burkina Faso. This information comes from cybersecurity firm Kaspersky, which has been tracking the group’s activities.

In addition to NightLedger, the attackers employ two custom WebSocket tunnelers, BridgeHead and ArcBridge, to ensure persistent and covert network access. These tools are part of a broader espionage toolkit designed to extract sensitive information from compromised systems.

Technical Details of NightLedger

NightLedger is a sophisticated Windows backdoor capable of executing commands, gathering system information, and capturing screenshots. It operates by connecting to an external server over HTTPS to execute commands, similar to the previously observed TWOSTROKE backdoor.

The malware’s functionality includes process execution, file manipulation, and data exfiltration. It also allows the threat actor to remotely update its operational parameters and maintain its presence on the victim’s network.

Methods of Initial Compromise

Although the initial access method remains unclear, Nimbus Manticore is known to use targeted phishing campaigns. These campaigns often mimic well-known brands and job platforms, redirecting victims to malicious websites disguised as legitimate services.

The attackers then leverage these deceptive tactics to deliver their payloads, including the NightLedger backdoor, through DLL side-loading techniques. This approach allows them to bypass security measures and establish a foothold in the targeted network.

Advanced Tunneling Techniques

BridgeHead and ArcBridge, the group’s custom tunneling tools, facilitate covert communication between the compromised systems and the attackers’ command-and-control servers. By relaying traffic through the victim’s network, these tools obfuscate the source of the malicious activity.

This strategy underscores the threat actor’s continued reliance on tunneling utilities, as seen in their previous operations involving bespoke tools like LIGHTRAIL and POLLBLEND.

Conclusion and Outlook

The revelations about Nimbus Manticore’s recent campaign highlight the persistent threat posed by state-sponsored actors. Their use of advanced malware and tunneling techniques demonstrates a high level of sophistication aimed at evading detection and maintaining long-term access to sensitive networks.

As cybersecurity experts continue to unravel these complex attacks, organizations must remain vigilant and enhance their defensive measures to protect against such sophisticated threats.

The Hacker News Tags:Africa, covert operations, cyber espionage, cyber threats, Cybersecurity, Hacking, Kaspersky, Malware, Middle East, NightLedger, Nimbus Manticore, Phishing, South Asia, WebSocket

Post navigation

Previous Post: Chinese Firm Allegedly Builds Network for PLA Cyber Ops
Next Post: Frenos Secures $1.52M to Enhance OT Security Innovations

Related Posts

Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist The Hacker News
Government Pays M to Prevent Data Leak by Kairos Group Government Pays $1M to Prevent Data Leak by Kairos Group The Hacker News
RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers RondoDox Botnet Exploits Critical React2Shell Flaw to Hijack IoT Devices and Web Servers The Hacker News
Google Cloud Vertex AI SDK Flaw Exposed Model Uploads Google Cloud Vertex AI SDK Flaw Exposed Model Uploads The Hacker News
Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with 0K in Rewards Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards The Hacker News
Understanding MFA Prompt Bombing: Risks and Solutions Understanding MFA Prompt Bombing: Risks and Solutions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs
  • Hackers Exploit CEO Identity in Major Email Scam
  • Phishing Study Reveals New Insights on Security Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark