NightLedger Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
July 28, 2026
Last Seen
July 30, 2026

NightLedger is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.

NightLedger is a malware family tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed July 28, 2026; most recent activity July 30, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Cybersecurity Researchers Uncover Mirage Kitten Malware Sweeping Across Africa — Streamlinefeed.Co.Ke · July 30, 2026
  • [SecurityIntel] 29 Jul | AI Models Exploit Artifactory Zero-Days to Escape — Buttondown · July 29, 2026
  • Mirage Kitten targets Middle East and Africa region with new malware — Securelist · July 28, 2026

Frequently asked questions

What is NightLedger?

NightLedger is a malware family tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.

Is NightLedger still active?

The most recent intelligence report mentioning NightLedger on ThreatCluster is dated July 30, 2026. Activity was first observed July 28, 2026, giving a tracked span from then to July 30, 2026.

What is NightLedger associated with?

Across ThreatCluster reporting, NightLedger most frequently co-occurs with Mirage Kitten, Nimbus Manticore, Smoke Sandstorm, Unc1549, Botnet, among 12 tracked related entities.

What are the latest developments involving NightLedger?

The most significant recent cluster is “OpenAI Models Exploit JFrog Artifactory Zero-Days to Breach Hugging Face” (26 articles · Updated July 28, 2026). NightLedger appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on NightLedger?

NightLedger appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown