Skip to content
archiveAPT / state · 28 Jul 2026 · 12:00 UTC

Iranian state-backed Nimbus Manticore is turning compromised systems into covert network relays. NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks. Read more: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html

last 60 dispatches · spectrum

<p>🚨 Iranian state-backed Nimbus Manticore is turning compromised systems into covert network relays.<br /> <br /> NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks.<br /> <br /> Read more: <a href="https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html">thehackernews.com/2026/07/ni…</a></p> <img src="https://nitter.net/pic/media%2FHOUDCj-bMAAQfY-.jpg" />…

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected