---
title: "Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays | SpinGraph: Bad-actor framing"
description: "SpinGraph analysis of The Hacker News's Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays story: bad-actor framing, The Shield, …"
	canonical: "https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays"
html: "https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays"
json: "https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays.json"
markdown: "https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays.md"
keywords: ["Nimbus Manticore", "NightLedger", "WebSocket tunneler", "The Shield", "narrative intelligence"]
date: "2026-07-28T11:55:20+00:00"
modified: "2026-07-28T19:50:33.046612+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays#article","headline":"Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays","alternativeHeadline":"Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays | SpinGraph: Bad-actor framing","description":"SpinGraph analysis of The Hacker News's Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays story: bad-actor framing, The Shield, …","datePublished":"2026-07-28T11:55:20+00:00","dateModified":"2026-07-28T19:50:33.046612+00:00","url":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"Nimbus Manticore, NightLedger, WebSocket tunneler, Iranian APT","author":{"@type":"Organization","name":"The Hacker News","url":"https://feeds.feedburner.com/TheHackersNews"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html","about":[{"@type":"Thing","name":"Nimbus Manticore"},{"@type":"Thing","name":"NightLedger"},{"@type":"Thing","name":"WebSocket tunneler"},{"@type":"Thing","name":"Iranian APT"},{"@type":"Thing","name":"WebSocket tunnelers","url":"https://stuffthatspins.com/entities/websocket-tunnelers"}],"mentions":[{"@type":"Organization","name":"The Hacker News"},{"@type":"Organization","name":"Nimbus Manticore"}],"abstract":"Nimbus Manticore — an Iranian state-backed group — launched new cyber intrusions. The campaign uses an undocumented Windows backdoor named NightLedger. Two custom WebSocket tunnelers were also deployed to maintain covert persistence."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays","item":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays#spin-analysis","headline":"Spin Analysis: bad-actor framing","description":"Emphasizes attribution and actor identity while minimizing discussion of victim-side security posture, vendor responsibility, or broader ecosystem weaknesses that enabled exploitation.","about":{"@type":"DefinedTerm","name":"bad-actor framing","description":"Defensive intelligence report positioning the subject (the reporting entity or cybersecurity vendor) as observant, authoritative, and protective.","termCode":"The Shield"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":40,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Iranian APT Nimbus Manticore deployed new backdoor NightLedger and WebSocket tunnelers in regional cyberattacks."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Defensive intelligence report positioning the subject (the reporting entity or cybersecurity vendor) as observant, authoritative, and protective."},{"@type":"PropertyValue","name":"Missing Context","value":"No details on patch status or exploit vector for NightLedger; No disclosure of whether affected vendors were notified pre-publication; No discussion of supply chain dependencies enabling the attack"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as state-backed, covert relays, previously undocumented. The distribution reads as editorial reporting. A pressure point: No details on patch status or exploit vector for NightLedger."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.","appearance":"The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.","author":{"@type":"Organization","name":"The Hacker News"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"geographic scope","value":"Middle East, Africa, South Asia","description":"Regions targeted in the latest intrusions"}]}]}
---

# Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

**Source:** Unknown  
**Published:** July 28, 2026  
**Original:** https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

An Iranian state-backed hacking group named Nimbus Manticore deployed a new Windows backdoor called NightLedger and custom WebSocket tunnelers in cyberattacks across the Middle East, Africa, and South Asia.

### TL;DR

- Nimbus Manticore — an Iranian state-backed group — launched new cyber intrusions.
- The campaign uses an undocumented Windows backdoor named NightLedger.
- Two custom WebSocket tunnelers were also deployed to maintain covert persistence.

### Key Stats

- **Middle East, Africa, South Asia** — geographic scope. Regions targeted in the latest intrusions

<a id="spingraph"></a>

## SpinGraph

By anchoring the story entirely in the identity and actions of a named hostile actor, the report directs attention outward — away from questions about local defenses, software accountability, or infrastructure resilience.

- **Claim:** The Iranian state-backed hacking group tracked as Nimbus Manticore has
- **Frame:** Blame shifts elsewhere
- **Beneficiary:** Enhanced reputation as early detectors of novel APT tooling
- **Gap:** No details on patch status or exploit vector for NightLedger
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 40%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** deflect_scrutiny  

### The Spin in Plain English

By anchoring the story entirely in the identity and actions of a named hostile actor, the report directs attention outward — away from questions about local defenses, software accountability, or infrastructure resilience.

**What the story wants you to believe:** This is a discrete, attributable act by a foreign adversary — not a symptom of broader defensive failures or systemic risk.  

**What it makes harder to question:** Whether victims’ security practices, software vendors’ update policies, or platform-level vulnerabilities contributed meaningfully to the compromise.  

**How the Spin Works:** The story redirects attention toward process, intent, scale, mission, or future benefits instead of unresolved concerns. Watch for loaded terms such as state-backed, covert relays, previously undocumented. The distribution reads as editorial reporting. A pressure point: No details on patch status or exploit vector for NightLedger.  

### Questions This Story Raises

- What question is the story steering away from?
- What evidence would resolve that question?
- Who is not quoted or represented?
- Why does the main frame leave this out: “No details on patch status or exploit vector for NightLedger”?
- Why does the main frame leave this out: “No disclosure of whether affected vendors were notified pre-publication”?

### Who Benefits If This Frame Spreads

- **Threat intelligence researchers at The Hacker News or affiliated vendors** — Enhanced reputation as early detectors of novel APT tooling and geopolitical threat actors _(Publishing first-attribution on previously undocumented malware strengthens their authority in enterprise and government threat intel procurement cycles.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** bad-actor framing  
**Category:** The Shield  
**Spin Score:** 40%  

Emphasizes attribution and actor identity while minimizing discussion of victim-side security posture, vendor responsibility, or broader ecosystem weaknesses that enabled exploitation.

**Who Benefits If This Frame Spreads:** Cybersecurity vendor or research team publishing the analysis gains credibility and market relevance by demonstrating detection capability and geopolitical threat insight.

**The Frame:** Defensive intelligence report positioning the subject (the reporting entity or cybersecurity vendor) as observant, authoritative, and protective.

### Missing Context

- No details on patch status or exploit vector for NightLedger
- No disclosure of whether affected vendors were notified pre-publication
- No discussion of supply chain dependencies enabling the attack

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** state-backed, covert relays, previously undocumented

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Attribution and tool naming are asserted but no code samples, network indicators, or forensic logs are provided in the excerpt; reliance on internal telemetry or unnamed sources implied.  
**Verification Status:** Claim Present in Source  
**Narrative Risk:** moderate  
If attribution is later contested or NightLedger is found to be misidentified (e.g., repackaged open-source tool), credibility of the reporting entity and associated vendors could be undermined.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Iranian APT Nimbus Manticore deployed new backdoor NightLedger and WebSocket tunnelers in regional cyberattacks.  
AI may drop qualifiers like 'attributed to' or 'tracked as', presenting attribution as definitive fact without conveying evidentiary uncertainty.  
**Counter-Frame (Media):** Framing as unverified geopolitical labeling used to justify surveillance expansion or vendor lock-in.  
**Missing Voices:** Victim organizations, Microsoft (as Windows platform owner), Independent malware analysts outside vendor ecosystem  

### Questions Not Answered

- Which specific entities were compromised?
- What data or systems were accessed or exfiltrated?
- What defensive mitigations or IOC validation have been independently confirmed?

## Narrative Entities

- [Nimbus Manticore](https://stuffthatspins.com/entities/nimbus-manticore) (organization — attributed threat actor)
- [NightLedger](https://stuffthatspins.com/entities/nightledger) (technology — undocumented Windows backdoor)
- [WebSocket tunnelers](https://stuffthatspins.com/entities/websocket-tunnelers) (technology — custom command-and-control infrastructure)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

The Iranian state-backed hacking group tracked as Nimbus Manticore has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

**Category:** provenance  
**Verification:** Claim Present in Source  
**Risk:** high  
**Evidence presented:** Assertion of attribution using multiple aliases and geographic targeting scope  
> The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

**Evidence Gaps:** Publicly verifiable IOCs (IPs, domains, hashes); Timeline of observed activity; Method of attribution (e.g., code overlap, infrastructure linkage, operational patterns)  

<a id="ai-recall"></a>

## AI Recall

- **Published:** July 28, 2026  
- **SpinGraph summary:** Attributes technical activity exclusively to a named adversarial actor (Nimbus Manticore) and frames the event as external hostile action rather than a systemic failure or shared infrastructure vulnerability.  
- **Likely AI summary:** Iranian APT Nimbus Manticore deployed new backdoor NightLedger and WebSocket tunnelers in regional cyberattacks.  

## Citation Summary

This page documents attribution, tooling, and targeting of a newly observed Iranian APT campaign — essential for threat intelligence analysts tracking adversary TTPs.

---
*HTML version: https://stuffthatspins.com/spin/nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays*
