Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

A new and highly sophisticated attack vector has emerged, dubbed Nimbus Manticore, which exploits vulnerabilities discovered by artificial intelligence models to turn victim systems into covert relays for malicious activities. The attackers behind this operation have been using a tool called NightLedger to compromise networks, leaving organizations vulnerable to further breaches.

Nimbus Manticore is a complex threat that leverages the capabilities of AI-powered vulnerability scanning tools to identify and exploit previously unknown vulnerabilities in software applications. These AI models can analyze vast amounts of data to pinpoint weaknesses that human security professionals might miss. The attackers then use this information to develop targeted attacks, often through custom-built malware.

The affected organizations include a mix of private companies and government agencies from various industries, including finance, healthcare, and technology. These entities have reported experiencing unusual network activity, which has been linked to the NightLedger tool. Upon closer inspection, researchers discovered that the attackers had established covert relay channels within these networks, allowing them to bypass traditional security measures.

The mechanism behind Nimbus Manticore’s attacks is based on a concept called “zero-day” exploitation, where vulnerabilities are exploited before patches or fixes become available. In this case, the AI-powered vulnerability scanning tools have accelerated the discovery process, making it easier for attackers to identify and target these weaknesses. The use of NightLedger enables the attackers to maintain persistence within compromised networks, creating a backdoor for further malicious activities.

The severity of Nimbus Manticore’s impact is heightened by its ability to evade traditional detection methods. As AI-powered vulnerability scanning tools become more widespread in cybersecurity, it’s essential that organizations adapt their strategies to stay ahead of these threats. This includes implementing proactive measures such as continuous monitoring, threat hunting, and regular security assessments.

In the face of this evolving threat landscape, it’s crucial for organizations to prioritize security awareness and preparedness. By staying informed about emerging threats like Nimbus Manticore and taking steps to address vulnerabilities in a timely manner, companies can reduce their exposure to these types of attacks. This entails not only deploying AI-powered vulnerability scanning tools but also developing incident response plans that account for the unique challenges posed by AI-driven attacks.


Source: The Hacker News — 2026-07-28