Security · 19h ago
Iranian Hackers Deploy NightLedger Backdoor in Multi-Region Attacks
Iranian state-backed group Nimbus Manticore has been linked to new attacks across the Middle East, Africa, and South Asia using a previously unseen Windows backdoor called NightLedger. The intrusions also employ two custom WebSocket tunnelers to turn victim systems into covert relays. The campaign targets entities in multiple regions, expanding the group's known operational scope.
Meridian48 take
The use of custom WebSocket tunnelers suggests a sophisticated effort to maintain persistence and evade detection, but the geographic spread may indicate opportunistic targeting rather than a coordinated campaign.
Read the full reporting
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays →
The Hacker News
iranian-hackersnightledger-backdoor