Home/News/Nimbus Manticore Uses NightLedger to Hijack Systems
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Nimbus Manticore Uses NightLedger to Hijack Systems

Nimbus Manticore Uses NightLedger to Hijack Systems

The Iranian state-backed hacking group identified as Nimbus Manticore has been linked to a new wave of cyberattacks impacting entities in the Middle East, Africa, and South Asia. This threat actor is also known by several other monikers, including GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, indicating a sophisticated and persistent operational presence. The recent intrusions are characterized by the deployment of a previously undocumented Windows backdoor, named NightLedger, which serves as the primary tool for establishing and maintaining unauthorized access to victim systems.

In addition to NightLedger, Nimbus Manticore employs two custom-built WebSocket tunnelers. These tunnelers are crucial for creating covert communication channels, allowing the attackers to exfiltrate data and issue commands without detection. The use of WebSocket technology is particularly noteworthy, as it can often blend in with legitimate web traffic, making it harder for security defenses to identify and block. The primary objective appears to be the transformation of compromised systems into covert relays. This means that the victims' own infrastructure is leveraged to mask the origin of subsequent malicious activities, further obscuring the attackers' true location and identity. This tactic significantly complicates incident response and attribution efforts.

The specific targets and the full scope of the campaign remain under active investigation, but the geographical spread suggests a broad strategic interest in the targeted regions. The sophistication of the tools, including the custom-developed NightLedger backdoor and WebSocket tunnelers, points to a well-resourced and technically adept adversary. The attribution to Nimbus Manticore, a group with known ties to the Iranian government, aligns with broader geopolitical tensions and cyber espionage activities observed in the region. The group's history of targeting critical infrastructure and government entities underscores the potential severity of these latest attacks. Security researchers are actively analyzing the malware samples to understand the full capabilities of NightLedger and the tunnelers, aiming to develop effective detection and mitigation strategies. The ongoing analysis is expected to reveal more about the specific vulnerabilities exploited and the ultimate goals of Nimbus Manticore's operations in these regions. The use of compromised systems as relays is a common tactic in advanced persistent threats (APTs) to maintain long-term access and evade detection by security monitoring tools. This strategy allows attackers to pivot to other networks or conduct further attacks from seemingly legitimate IP addresses, creating a significant challenge for defenders.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next