Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

Nimbus Manticore Targets MENA With NightLedger Backdoor

Zscaler attributes fresh Middle East, Africa, and South Asia intrusions to Iranian APT Nimbus Manticore, deploying new Windows backdoor NightLedger.

Nimbus Manticore Targets MENA With NightLedger Backdoor
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 2 min read

Zscaler ThreatLabz confirmed it July 28. Nimbus Manticore — Iranian state-backed, tracked also as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549 — is running an active intrusion campaign against entities across the Middle East, Africa, and South Asia. The toolkit includes a previously undocumented Windows backdoor and two custom WebSocket tunnelers.

The attribution is Zscaler’s. Cross-vendor alias unification should be verified against your own intel feeds before operationalizing it.

NightLedger

The backdoor is named NightLedger. Previously undocumented — no prior public reporting on it before this week. Specific capabilities beyond backdoor access are not yet in public reporting. Full technical analysis, including indicators of compromise, is in the Zscaler ThreatLabz research via The Hacker News.

The two WebSocket tunnelers accompanying NightLedger: names not specified in current public reporting. Function is likely C2 channel obfuscation via WebSocket over HTTPS — a standard approach to blend malicious traffic with legitimate web traffic. Specific implementation details unconfirmed. Treat as inferred operational pattern until Zscaler publishes the full technical breakdown.

Targets

Middle East, Africa, South Asia — confirmed in Zscaler reporting. Entity types and specific sectors are not named in current public disclosures. UNC1549’s historical targeting has included government, defense, and critical infrastructure in the region. That is prior attribution, not confirmed specific to this campaign wave. Label it accordingly.

Detection

NightLedger is newly named. Signature coverage will lag the disclosure — behavioral detection is the better immediate layer.

Pull the IOC set from the Zscaler primary report before writing detection rules. Priority behavioral signals:

  • Anomalous outbound WebSocket connections from Windows workstations to external endpoints
  • Unexpected persistence artifacts: new scheduled tasks, services, or registry run keys without a corresponding deployment record
  • Suspicious Windows process activity correlated with new external network connections

If your environment includes any footprint in the targeted regions — or connectivity to partners, suppliers, or clients operating there — treat this as active now. Attribution to an Iranian state-backed actor does not change the detection posture; the IOC sweep and behavioral monitoring apply regardless.

Context

The region is seeing concurrent APT activity from multiple actors. A separate East Asian threat cluster deploying TELESHIM, MIXEDKEY, and BINDCLOAK malware against Middle East government entities was documented July 27. Different actor. Different toolset. Same geography. Both warrant tracking if regional exposure applies to your environment.

Source: The Hacker News, citing Zscaler ThreatLabz research. July 28, 2026.

Found this useful? Share it.