logo

DIANNA Explains 4: Nimbus Manticore—Monstrous Malware

ID: acea7be7-a5a5-506f-a4c2-3fe43b1b7b0f

STIX ID: report--acea7be7-a5a5-506f-a4c2-3fe43b1b7b0f

Feed Name: Deep Instinct Blog

Threat Score
80/100

Date Published: 2025-12-03

Date Updated: 2026-04-27

Author: DIANNA

...
...

Nimbus Manticore is a highly obfuscated 64-bit Windows malware attributed to an Iranian-backed actor that uses encrypted/packed sections, dynamic component loading (including a suspicious DLL 'unbcl-new6.dll'), sandbox-evasion, RPC-based lateral movement, and privilege escalation to establish persistent, network-wide footholds; Deep Instinct was reportedly the only vendor on VirusTotal to detect it for a full week, underscoring weaknesses in endpoint- and sandbox-focused defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.