Return to Threats

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

thehackernews.com 2026-07-28 malicious AI use High

What Happened

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,

Why It Matters

The article reports that the Iranian state-backed group Nimbus Manticore (also known as UNC1549, Smoke Sandstorm, and others) is using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, to conduct espionage across the Middle East, Africa, and South Asia.[1][2][3] NightLedger supports extensive remote access capabilities (command execution, file operations, system discovery, screenshots), while the tunnelers turn compromised systems into covert relay nodes for anonymized traffic and persistent C2 access.[1][2][3] From a RealGround perspective, this illustrates the increasing sophistication and stealth of state-aligned offensive cyber tooling, some of which is being enhanced and iterated rapidly in ways consistent with AI-assisted development trends seen in Nimbus Manticore’s broader toolset.[5][8][10] Organizations operating in or connected to the targeted regions should assume capable, stealthy adversaries and use continuous AI-informed red teaming and readiness assessments to tune detections for new backdoors and tunneling patterns, improve phishing resilience, and update incident response playbooks for relay-node abuse of their

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html

Talk to AI CISO