Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Nimbus Manticore expands infrastructure and malware arsenal

  • What: Iranian APT group Nimbus Manticore expands infrastructure and malware
  • Impact: Targets global infrastructure with new backdoors and tunneling tools
Read Full Article →

Threat Intelligence Nimbus Manticore expands infrastructure and malware arsenal August 26, 2026 Share By SC Staff Nimbus Manticore, an Iranian state-sponsored hacking group linked to the Islamic Revolutionary Guard Corps, has expanded its operational infrastructure and deployed previously undocumented malware. Group-IB's analysis reveals the group, also known as GalaxyGato and Mirage Kitten, is one of the most active Iranian APT groups, with further coverage provided by The Hacker News. Nimbus Manticore, associated with the Tortoiseshell (Imperial Kitten) cluster, has been observed using an SSH-based tunneling utility and a C++ backdoor similar to its existing TWOSTROKE implant. This expanded infrastructure, found across Europe and the Middle East, suggests a widening target profile. The group has a history of employing social engineering tactics, such as the "Dream Job" campaign, to deliver malware. Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia. The identified tools, including the reverse SSH tunneling tool and the backdoor capable of file manipulation and remote command execution, highlight the actor's evolving capabilities and persistent efforts to maintain access to compromised systems. Source: The Hacker News SC Staff Related SOC From tool stack to defense system: Connecting the security dots Paul Wagenseil August 25, 2026 How well do your various security tools play together? AI can organize them into an army. Threat Intelligence Attackers use FTP banners to hide new E4del and PINHOLE RATs SC Staff August 21, 2026 The attack chain begins with a ZIP archive, likely distributed via phishing, which initiates an LNK-based infection. Threat Intelligence Network of 77 Firefox extensions linked to crypto theft uncovered SC Staff August 20, 2026 Socket researchers identified 40 malicious extensions and 37 others disguised as unrelated utilities, all linked through shared code, infrastructure, and publishing artifacts. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Deauthentication Attack Deepfake Defacement Distributed Scans Domain Hijacking Fault Line Attacks Google Hacking Reconnaissance You can skip this ad in 5 seconds

Share this article