Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Summary
The Iranian state-backed hacking group Nimbus Manticore (aka GalaxyGato) has been linked to a new wave of attacks targeting organizations across the Middle East, Africa, and South Asia. These intrusions deploy a novel Windows backdoor named NightLedger and two custom WebSocket tunnelers. A key tactic involves transforming compromised systems into covert relays for malicious activity.
IFF Assessment
The article describes new attack methodologies and tools from a sophisticated state-backed threat actor, posing a heightened risk to targeted organizations.
Defender Context
Defenders need to be aware of the new TTPs employed by Nimbus Manticore, particularly the NightLedger backdoor and the use of compromised systems as covert relays. Organizations in the Middle East, Africa, and South Asia should enhance their defenses and network monitoring to detect these specific threats. Implementing strong network segmentation, egress filtering, and advanced endpoint detection solutions can help mitigate the risks associated with such sophisticated attacks.