The Iranian state backed hacking group, “Nimbus Manticore“, has been attributed to a new campaign of cyberattacks against entities across the Middle East, Africa and South Asia. Nimbus Manticore focuses its activities on the aviation, telecommunications, and defense sectors throughout the Middle East. The group typically utilizes targeted phishing campaigns, fake job portals, and multi-stage malware to gain persistent access to desired networks and exfiltrate sensitive data.
According to the Hacker News, the Nimbus Manticore hacking group has exploited a backdoor in the Windows operating system called “NightLedger” and tunnelers “BridgeHead” and “ArcBridge” to maintain its persistent access. The hacking group has targeted entities in Egypt, government entities in Jordan, Tanzania, aviation organizations in Pakistan, telecommunications companies in Ethiopia and financial sector entities in Burkina Faso.
The discovery of a new malware called “HOLLOWGRAPH” led to secondary investigations, which linked the disclosure to the Iranian hacking group “Cavern Manticore.“
Despite increasing regional tensions and the ongoing Iran-Israel war, Nimbus Manticore continues its cyber operations across the Middle East, showcasing the country’s cyber capabilities on a global scale.





