Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

July 28, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Government and critical infrastructure entities in the Middle East, Africa, and South Asia
Incident: A state-sponsored espionage campaign deploying new backdoors and tunneling tools for covert access.
Impact: Potential for extensive data exfiltration and long-term strategic espionage across multiple critical sectors.
Attacker: Nimbus Manticore
Analysis: Nimbus Manticore is employing a sophisticated toolset including the NightLedger backdoor and custom WebSocket tunnelers to bypass traditional detection. The group notably repurposes Microsoft 365 calendars as covert C2 channels, scheduling events far into the future to avoid user detection. This campaign demonstrates high operational security focused on long-term persistence and covert data exfiltration.
Recommendations: Monitor for unusual Microsoft Graph API calls and unexpected calendar events dated far into the future.; Implement strict DLL side-loading protections and monitor for unauthorized DLL loads in trusted processes.; Enhance network monitoring for non-standard WebSocket traffic to unknown external endpoints.
Source: The Hacker News / Kaspersky

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *