Malware
NimbleMamba
NimbleMamba is a new implant used by TA402/Molerats group as replacement of LastConn.
NimbleMamba is a Windows malware family operated by Molerats.
Background
NimbleMamba is an implant the TA402/Molerats group adopted to take over from LastConn. It applies guardrails that confirm a victim falls inside the actor's intended target region. Coded in C#, it is distributed as an obfuscated .NET executable, with SmartAssembly observed as one of the obfuscators in use.
Source: Malpedia (Fraunhofer FKIE).