hacker-news · Crawled Jul 28, 2026
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
1 IoCs 2 Actors
Read original article ↗
AI Summary
Iranian state-backed threat actor Nimbus Manticore is conducting cyber espionage operations across the Middle East, Africa, and South Asia using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge. The group leverages phishing lures and fake videoconferencing pages to deliver payloads, which are executed via DLL side-loading. NightLedger enables reconnaissance, command execution, file operations, and screenshot capture, while BridgeHead and ArcBridge establish covert relay tunnels through victim systems for operator-controlled traffic.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | unbcl.dll | Details → |
MITRE ATT&CK TTPs 27 techniques
T1001.002 Steganography · Command And Control T1003 OS Credential Dumping · Credential Access T1005 Data from Local System · Collection T1016 System Network Configuration Discovery · Discovery T1021.006 Windows Remote Management · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1040 Network Sniffing · Credential Access T1053.003 Cron · Execution T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1085 T1085 T1087.001 Local Account · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1129 Shared Modules · Execution T1132.001 Standard Encoding · Command And Control T1133 External Remote Services · Persistence T1543.003 Windows Service · Persistence T1566 Phishing · Initial Access T1573 Encrypted Channel · Command And Control T1574.002 DLL Side-Loading · Persistence