How Nimbus Manticore Turns Your System Into a Covert Relay

ยท
Listen to this article~5 min
How Nimbus Manticore Turns Your System Into a Covert Relay

A state-backed Iranian hacking group is using a new Windows backdoor called NightLedger to turn victim systems into covert relays. Learn how this works and how to protect your antidetect browser setup.

A state-backed hacking group out of Iran has been linked to a new wave of attacks. They are targeting organizations across the Middle East, Africa, and South Asia. This group, known as Nimbus Manticore, is using a previously unseen Windows backdoor called NightLedger. They also deploy two custom WebSocket tunnelers to stay hidden. If you work in cybersecurity or manage digital operations, this matters. It shows how sophisticated attackers are getting at turning victim machines into stealthy relay points. These relays can then be used to launch further attacks, steal data, or hide their tracks. ### What Is Nimbus Manticore? Nimbus Manticore goes by many names. You might know them as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, or UNC1549. They are an Iranian state-backed hacking group. Their focus has been on espionage and disruption, hitting targets in government, energy, and tech sectors. Their latest campaign uses a fresh set of tools. The main one is NightLedger, a Windows backdoor that gives attackers remote control over infected systems. Alongside it, they use two WebSocket tunnelers. These tunnelers create encrypted pathways for data to move in and out without raising alarms. ### How NightLedger Works NightLedger is not your average malware. It is designed to be stealthy. Once it infects a system, it can: - Execute commands remotely - Upload and download files - Capture keystrokes and screen activity - Turn the victim machine into a relay for other attacks This last capability is key. Instead of just stealing data, attackers use your system to hide their own traffic. They bounce commands through your network, making it harder to trace back to them. ### The Role of WebSocket Tunnelers The two custom WebSocket tunnelers are the backbone of this operation. They keep communication alive between the attacker and the victim. WebSocket technology is common in web apps, so traffic from these tunnelers often blends in with normal internet activity. This makes detection tough. Traditional security tools might not flag it as suspicious because it looks like regular web traffic. Only deeper inspection reveals the malicious intent. ### Why This Matters for Antidetect Browser Users If you use antidetect browsers to manage multiple online identities, you should be extra careful. Attackers like Nimbus Manticore often target professionals who handle sensitive data. Your system could become a relay without you knowing. Here are some practical steps to stay safe: - Keep your antidetect browser updated to the latest version - Use strong, unique passwords for each profile - Enable two-factor authentication wherever possible - Monitor your system for unusual network activity - Consider running your antidetect browser in a sandboxed environment These steps won't guarantee complete safety, but they reduce your risk significantly. ### A Closer Look at the Attacks The attacks are not random. They target specific organizations in the Middle East, Africa, and South Asia. The goal appears to be long-term espionage rather than quick financial gain. By turning victim systems into relays, attackers can launch follow-up attacks that are harder to trace. One security researcher noted: "This group is methodical. They invest time in custom tools and infrastructure. Their patience makes them dangerous." ### The Bigger Picture This campaign is a reminder that cyber threats are evolving. Attackers no longer just break in and steal data. They use your own systems against you. They turn your machines into tools for their next attack. For anyone using antidetect browsers or managing digital privacy, staying informed is half the battle. Know the threats. Understand the tactics. And always question unexpected activity on your network. ### Final Thoughts NightLedger and the WebSocket tunnelers show how creative attackers can get. They are not just relying on old tricks. They build custom tools to fit their needs. That makes them harder to stop. But you can fight back. Stay vigilant. Keep your software updated. And never assume your system is safe just because you have a good antivirus. The best defense is awareness. Stay safe out there. *This article is for informational purposes only. Always consult with a cybersecurity professional for advice tailored to your situation.*