Iran-Linked Hackers Deploy 'NightLedger' Backdoor Against Middle East, Africa Targets
Nimbus Manticore is running a fresh campaign with a new Windows backdoor and hidden tunnels that turn victim machines into relays.

Key points
- An Iranian government-linked hacking crew known as Nimbus Manticore is running a new espionage campaign across the Middle East, Africa, and South Asia.
- The group has deployed a previously unseen Windows backdoor, meaning a hidden program that gives attackers remote control, called NightLedger.
- Two custom WebSocket tunneling tools let the attackers route their traffic through infected machines, making the activity harder to spot.
- The same crew is tracked under several other names: GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549.
- Targets appear to be organisations of interest to Iranian intelligence, not consumers.
An Iranian state-backed hacking group has quietly rolled out a new toolkit against targets in the Middle East, Africa, and South Asia, according to reporting from The Hacker News. The activity is tied to a crew that researchers most often call Nimbus Manticore, though it also travels under GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and the Mandiant designation UNC1549.
The headline finding: a Windows backdoor that has not been publicly documented before, named NightLedger. Alongside it, the group is using two custom tunneling tools built on WebSockets (a common web protocol that keeps a live connection open between two computers).
In plain terms, the tunnelers turn a hacked computer inside a target company into a quiet relay point. The attackers' traffic gets mixed in with normal-looking web activity, which makes it far harder for defenders to notice something is wrong.
Who is Nimbus Manticore?
It is a hacking group that Western researchers link to the Iranian state. The crew has a long track record of going after aerospace, defence, and telecommunications firms, and it tends to focus on espionage rather than theft or extortion.
The many aliases reflect the fact that different security companies name the same crew differently. Microsoft calls it Smoke Sandstorm. Google's Mandiant unit tracks it as UNC1549. Check Point uses Nimbus Manticore. They are describing the same people.
What does the new backdoor actually do?
NightLedger is a remote-control tool for Windows machines. Once it is installed on a victim's computer, the attackers can run commands, move files, and stage further tools without the user knowing.
A backdoor on its own is not new. What matters here is that NightLedger has not been seen before in public reporting, so most security products will not recognise it out of the box. That gives the operators a window of quiet access until detection rules catch up.
Why the WebSocket tunnels matter
The two custom tunnelers are arguably the more interesting piece. They let Nimbus Manticore push its command traffic through infected systems and out to the wider internet, disguised as ordinary web sessions.
For a defender staring at network logs, that traffic looks a lot like a browser talking to a normal website. The victim's own machine becomes part of the attackers' infrastructure, a covert relay in someone else's spy network.
Who is at risk?
| Item | Detail |
|---|---|
| Group | Nimbus Manticore (also UNC1549, Smoke Sandstorm) |
| Attribution | Iranian state-linked |
| New malware | NightLedger (Windows backdoor) |
| Extra tooling | Two custom WebSocket tunnelers |
| Regions targeted | Middle East, Africa, South Asia |
The targeting pattern points at organisations, governments, defence suppliers, telecoms, and similar, rather than ordinary consumers. If you are a nurse or a shop owner reading this, you are almost certainly not on the list.
That said, staff at any organisation working in those sectors, or supplying one, should treat unexpected login prompts, recruiter messages on LinkedIn, and unusual file attachments with real suspicion. Nimbus Manticore has a history of using fake job offers to lure engineers into opening booby-trapped files.
Security teams at exposed organisations should hunt for unusual outbound WebSocket connections and unknown persistent services on Windows endpoints. Public technical indicators from the researchers who found the campaign are the fastest way to start that hunt.



