Skip to main content
CyberSingle-sourceMediumDeveloping
5.5

Iranian APT Nimbus Manticore deploys new modular malware for covert network relay

The Iranian state-backed threat actor Nimbus Manticore has introduced a new toolset, including the NightLedger backdoor and BridgeHead/ArcBridge tunneling modules, to transform compromised systems into covert network relays. This development marks an evolution in the group's persistence and exfiltration capabilities, allowing for more sophisticated obfuscation of command-and-control traffic.

The Hacker News3 days agoIRCredibility 52%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.5
Source

Related signals

8 found