Nimbus Manticore, an Iranian state-backed hacking group also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, has been linked to a new wave of cyberattacks. The activity reportedly targeted organizations and entities across the Middle East, Africa, and South Asia.
A key detail in the latest campaign is the use of a tool called NightLedger. According to the report, the malware was used in a way that helped convert compromised machines into covert relays, allowing attacker traffic to pass through victim systems rather than appearing to come directly from the operators.
That relay-style approach can make malicious activity harder to trace and may help threat actors blend into normal network traffic. It also suggests an effort to build persistence and operational flexibility inside affected environments, especially in regions where the group is said to be actively targeting organizations.
The attribution adds to the growing body of reporting around Nimbus Manticore and its many aliases, underscoring how the same threat cluster is tracked differently across the cybersecurity industry. While the trimmed report does not include full technical details, the campaign highlights continued concern over state-linked intrusion activity spanning multiple regions.