Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
Summary
Hide ▲
Show ▼
Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve covert access. The operation spans Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso and reaches into government, aviation, telecom, and financial targets. The access route remains unknown, but the intrusion set is already delivering malware built for reconnaissance, command execution, and operator-controlled tunneling. The activity increases the risk of persistent compromise and covert network relay from victim environments.
Related Happenings
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
How related:
The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.
About this happening:
The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityHow related: The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.
About this happening: The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim syst...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Earth Lusca Operation FishMedley espionage campaign
Campaign
H score38
First: 16.06.2026 12:44
Last: 16.06.2026 12:44
Sources 1
About this happening:
A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Earth Lusca Operation FishMedley espionage campaign
CampaignAbout this happening: A multi-country espionage campaign tied to Earth Lusca / FishMonger is now linked to Operation FishMedley, a January–October 2022 effort that reached seven organ...
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
TGR-STA-1030/UNC6619 Shadow Campaigns espionage operation
Campaign
H score30
First: 07.02.2026 17:09
Last: 07.02.2026 17:09
Sources 1
About this happening:
The TGR-STA-1030/UNC6619 operation Shadow Campaigns expanded a state-sponsored espionage effort that compromised at least 70 organizations across 37 countries, inc...
TGR-STA-1030/UNC6619 Shadow Campaigns espionage operation
CampaignAbout this happening: The TGR-STA-1030/UNC6619 operation Shadow Campaigns expanded a state-sponsored espionage effort that compromised at least 70 organizations across 37 countries, inc...
Timeline
-
28.07.2026 14:55 2 articles · 1h ago
Nimbus Manticore ties NightLedger and custom tunnelers to fresh covert-access campaign
Initial DisclosureNimbus Manticore, the Iranian state-backed group also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, is tied to fresh intrusions across the Middle East, Africa, and South Asia that use the previously undocumented Windows backdoor NightLedger and the custom WebSocket tunnelers BridgeHead and ArcBridge to maintain covert access. The disclosed targets include Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, spanning government, aviation, telecommunications, and financial-sector environments, while the initial access route remains unknown and NightLedger is delivered via DLL side-loading.
Show sources
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays — thehackernews.com — 28.07.2026 14:55
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays — thehackernews.com — 28.07.2026 14:55