Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Attributes technical activity exclusively to a named adversarial actor (Nimbus Manticore) and frames the event as external hostile action rather than a systemic failure or shared infrastructure vulnerability.
View original on thehackernews.comOverview
An Iranian state-backed hacking group named Nimbus Manticore deployed a new Windows backdoor called NightLedger and custom WebSocket tunnelers in cyberattacks across the Middle East, Africa, and South Asia.
TL;DR
- Nimbus Manticore — an Iranian state-backed group — launched new cyber intrusions.
- The campaign uses an undocumented Windows backdoor named NightLedger.
- Two custom WebSocket tunnelers were also deployed to maintain covert persistence.
Key Stats
Middle East, Africa, South Asia
geographic scope
Regions targeted in the latest intrusions
Questions Answered
Keywords
Narrative Frame
bad-actor framing
Spin Score
40%
Emphasizes attribution and actor identity while minimizing discussion of victim-side security posture, vendor responsibility, or broader ecosystem weaknesses that enabled exploitation.
What the story wants you to believe
This is a discrete, attributable act by a foreign adversary — not a symptom of broader defensive failures or systemic risk.
What it makes harder to question
Whether victims’ security practices, software vendors’ update policies, or platform-level vulnerabilities contributed meaningfully to the compromise.
How the spin works
The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as state-backed, covert relays, previously undocumented. The distribution reads as editorial reporting. A pressure point: No details on patch status or exploit vector for NightLedger.
Who Benefits If This Frame Spreads
Threat intelligence researchers at The Hacker News or affiliated vendors
Enhanced reputation as early detectors of novel APT tooling and geopolitical threat actors
Publishing first-attribution on previously undocumented malware strengthens their authority in enterprise and government threat intel procurement cycles.
The Frame
Defensive intelligence report positioning the subject (the reporting entity or cybersecurity vendor) as observant, authoritative, and protective.
Missing Context
- No details on patch status or exploit vector for NightLedger
- No disclosure of whether affected vendors were notified pre-publication
- No discussion of supply chain dependencies enabling the attack
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
By anchoring the story entirely in the identity and actions of a named hostile actor, the report directs attention outward — away from questions about local defenses, software accountability, or infrastructure resilience.
- Claim
The Iranian state-backed hacking group tracked as Nimbus Manticore has
The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
- Frame
Blame shifts elsewhere
Defensive intelligence report positioning the subject (the reporting entity or cybersecurity vendor) as observant, authoritative, and protective.
- Beneficiary
Enhanced reputation as early detectors of novel APT tooling
Threat intelligence researchers at The Hacker News or affiliated vendors — Enhanced reputation as early detectors of novel APT tooling and geopolitical threat actors
- Gap
No details on patch status or exploit vector for NightLedger
- AI Risk
AI may repeat the headline as fact
Iranian APT Nimbus Manticore deployed new backdoor NightLedger and WebSocket tunnelers in regional cyberattacks.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. | Assertion of attribution using multiple aliases and geographic targeting scope | Claim Present in Source | High | Publicly verifiable IOCs (IPs, domains, hashes); Timeline of observed activity; Method of attribution (e.g., code overlap, infrastructure linkage, operational patterns) |
The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
evidence: Assertion of attribution using multiple aliases and geographic targeting scope
"The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia."
Evidence Gaps
- Publicly verifiable IOCs (IPs, domains, hashes)
- Timeline of observed activity
- Method of attribution (e.g., code overlap, infrastructure linkage, operational patterns)
Fact Check Signals
0 of 1 claim matched · confidence: low · checked July 28, 2026
The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Defensive intelligence report positioning the subject (the reporting entity or cybersecurity vendor) as observant, authoritative, and protective.
Media / Reader Counter-Frame
Framing as unverified geopolitical labeling used to justify surveillance expansion or vendor lock-in.
Regulatory Counter-Frame
Questioning whether public attribution without coordinated disclosure violates responsible vulnerability handling norms or escalates cyber conflict.
AI Summary Frame
Omitting 'previously undocumented' nuance and presenting NightLedger as definitively novel when it may be obfuscated commodity malware.
Missing Voices
Questions Not Answered
- Which specific entities were compromised?
- What data or systems were accessed or exfiltrated?
- What defensive mitigations or IOC validation have been independently confirmed?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
31
Trigger score 0
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Iranian APT Nimbus Manticore deployed new backdoor NightLedger and WebSocket tunnelers in regional cyberattacks."
Concern: AI may drop qualifiers like 'attributed to' or 'tracked as', presenting attribution as definitive fact without conveying evidentiary uncertainty.
-
Published
Jul 28, 2026
-
Ingested
Jul 28, 2026
-
SpinGraph Created
Jul 28, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_nimbus_manticore_deploys_nightledger_and_turns_v
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
- 24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
- Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
- Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit
- Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO