Nimbus Manticore's Cyber Attacks Exploit New Malware to Target Global Entities
The Iranian state-backed hacking group Nimbus Manticore has launched a series of cyber attacks using a new Windows backdoor called NightLedger, along with custom WebSocket tunnelers BridgeHead and ArcBridge. These tools are designed to maintain covert access to targeted systems across the Middle East, Africa, and South Asia. The campaign targets various sectors, including government, aviation, telecommunications, and finance. The malware allows the attackers to execute commands, gather information, and maintain network access through compromised systems. The initial access method remains unknown, but the group is known for using phishing lures and malicious archives to infiltrate systems.