hacker-news · Crawled Jul 28, 2026
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
1 IoCs 2 Actors
Read original article ↗
AI Summary
Iranian state-backed threat actor Nimbus Manticore is conducting cyber espionage operations across the Middle East, Africa, and South Asia using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge. The group leverages phishing lures and fake videoconferencing pages to deliver payloads, which are executed via DLL side-loading. NightLedger enables reconnaissance, command execution, file operations, and screenshot capture, while BridgeHead and ArcBridge establish covert relay tunnels through victim systems for operator-controlled traffic.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | unbcl.dll | Details → |
MITRE ATT&CK TTPs 8 techniques
T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1085 T1085 T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1132.001 Standard Encoding · Command And Control T1566 Phishing · Initial Access T1573 Encrypted Channel · Command And Control