Find notable cyber news and cases, enriched with sources, timelines, and signals.

Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve covert access. The operation spans Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso and reaches into government, aviation, telecom, and financial targets. The access route remains unknown, but the intrusion set is already delivering malware built for reconnaissance, command execution, and operator-controlled tunneling. The activity increases the risk of persistent compromise and covert network relay from victim environments.

Related Happenings

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

How related: The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

About this happening: The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...

GoSerpent malware activity targeting Southeast Asian entities

Malware Activity
H score26 First: 17.07.2026 11:46 Last: 17.07.2026 11:46 Sources 1

About this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...

Earth Lusca Operation FishMedley espionage campaign

Campaign
H score38 First: 16.06.2026 12:44 Last: 16.06.2026 12:44 Sources 1

About this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...

Webworm multi-country targeting campaign against government and enterprise victims

Campaign
H score38 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...

TGR-STA-1030/UNC6619 Shadow Campaigns espionage operation

Campaign
H score30 First: 07.02.2026 17:09 Last: 07.02.2026 17:09 Sources 1

About this happening: The TGR-STA-1030/UNC6619 operation Shadow Campaigns expanded a state-sponsored espionage effort that compromised at least 70 organizations across 37 countries, inc...

Timeline

  1. 28.07.2026 14:55 2 articles · 1h ago

    Nimbus Manticore ties NightLedger and custom tunnelers to fresh covert-access campaign

    Initial Disclosure

    Nimbus Manticore, the Iranian state-backed group also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, is tied to fresh intrusions across the Middle East, Africa, and South Asia that use the previously undocumented Windows backdoor NightLedger and the custom WebSocket tunnelers BridgeHead and ArcBridge to maintain covert access. The disclosed targets include Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, spanning government, aviation, telecommunications, and financial-sector environments, while the initial access route remains unknown and NightLedger is delivered via DLL side-loading.

    Show sources