The Iranian state-backed hacking group tracked as Nimbus
Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle
Snail, and UNC1549) has been attributed to a fresh set of attacks
targeting entities across the Middle East, Africa, and South Asia.
The intrusions involve the use of a previously undocumented Windows
backdoor called NightLedger and two custom WebSocket
tunnelers,
Read more https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html

