Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Nimbus Manticore Targets Critical Sectors with New Malware

Nimbus Manticore Targets Critical Sectors with New Malware

Posted on July 28, 2026 By CWS

An Iranian state-sponsored hacking group known as Nimbus Manticore has been linked to a recent series of cyberattacks on organizations in the Middle East, Africa, and South Asia. Utilizing a newly discovered Windows backdoor called NightLedger, the group aims to maintain clandestine access to affected systems.

Targeted Regions and Sectors

The attacks have impacted a variety of sectors, including governments and small-to-medium businesses in Jordan and Tanzania, aviation firms in Pakistan, telecommunications in Ethiopia, and financial institutions in Burkina Faso. This information comes from cybersecurity firm Kaspersky, which has been tracking the group’s activities.

In addition to NightLedger, the attackers employ two custom WebSocket tunnelers, BridgeHead and ArcBridge, to ensure persistent and covert network access. These tools are part of a broader espionage toolkit designed to extract sensitive information from compromised systems.

Technical Details of NightLedger

NightLedger is a sophisticated Windows backdoor capable of executing commands, gathering system information, and capturing screenshots. It operates by connecting to an external server over HTTPS to execute commands, similar to the previously observed TWOSTROKE backdoor.

The malware’s functionality includes process execution, file manipulation, and data exfiltration. It also allows the threat actor to remotely update its operational parameters and maintain its presence on the victim’s network.

Methods of Initial Compromise

Although the initial access method remains unclear, Nimbus Manticore is known to use targeted phishing campaigns. These campaigns often mimic well-known brands and job platforms, redirecting victims to malicious websites disguised as legitimate services.

The attackers then leverage these deceptive tactics to deliver their payloads, including the NightLedger backdoor, through DLL side-loading techniques. This approach allows them to bypass security measures and establish a foothold in the targeted network.

Advanced Tunneling Techniques

BridgeHead and ArcBridge, the group’s custom tunneling tools, facilitate covert communication between the compromised systems and the attackers’ command-and-control servers. By relaying traffic through the victim’s network, these tools obfuscate the source of the malicious activity.

This strategy underscores the threat actor’s continued reliance on tunneling utilities, as seen in their previous operations involving bespoke tools like LIGHTRAIL and POLLBLEND.

Conclusion and Outlook

The revelations about Nimbus Manticore’s recent campaign highlight the persistent threat posed by state-sponsored actors. Their use of advanced malware and tunneling techniques demonstrates a high level of sophistication aimed at evading detection and maintaining long-term access to sensitive networks.

As cybersecurity experts continue to unravel these complex attacks, organizations must remain vigilant and enhance their defensive measures to protect against such sophisticated threats.

The Hacker News Tags:Africa, covert operations, cyber espionage, cyber threats, Cybersecurity, Hacking, Kaspersky, Malware, Middle East, NightLedger, Nimbus Manticore, Phishing, South Asia, WebSocket

Post navigation

Previous Post: Chinese Firm Allegedly Builds Network for PLA Cyber Ops
Next Post: Frenos Secures $1.52M to Enhance OT Security Innovations

Related Posts

Claude Opus 4.6 Uncovers 500+ Severe Flaws in Open-Source Software Claude Opus 4.6 Uncovers 500+ Severe Flaws in Open-Source Software The Hacker News
GitHub Probes Alleged Security Breach by TeamPCP GitHub Probes Alleged Security Breach by TeamPCP The Hacker News
.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL .NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL The Hacker News
Teen Hacker Extradited to U.S. for Cybercrime Charges Teen Hacker Extradited to U.S. for Cybercrime Charges The Hacker News
DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising DNS Poisoning Flaw, Supply-Chain Heist, Rust Malware Trick and New RATs Rising The Hacker News
RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops
  • Microsoft Launches MAI-Cyber-1-Flash for Enhanced Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New Tengu Botnet Enhances IoT Device Resilience
  • Frenos Secures $1.52M to Enhance OT Security Innovations
  • Nimbus Manticore Targets Critical Sectors with New Malware
  • Chinese Firm Allegedly Builds Network for PLA Cyber Ops
  • Microsoft Launches MAI-Cyber-1-Flash for Enhanced Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark