The Hacker News

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

Targets of the campaign include Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso, per Kaspersky.

"The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling," Kaspersky researchers Omar Amin and Vasily Berdnikov said.

The exact initial access method used in the attacks is presently unknown, although the adversary is known to employ highly tailored job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect recipients to malicious archives hosted on third-party file-sharing services.

NightLedger Backdoor

The as-yet-undetermined access route is then abused to deliver the malicious payloads, including NightLedger, which is launched as a DLL via DLL side-loading. The malware is designed to contact an external server over HTTPS to parse and run commands in a manner that's analogous to TWOSTROKE, another backdoor deployed by the threat actor in the past.

The list of supported commands is below:

  • Gather user and host identity information
  • Execute a process/program
  • List directories
  • Download a file to the infected system
  • Collect host and network information
  • Copy or delete files
  • Update beacon interval
  • Take a screenshot
  • Load a DLL
  • Terminate a process or thread
  • Upload file to the command-and-control (C2) server via an HTTP POST request
  • Enumerate logical drives
  • List processes
  • Collect C:\Windows\debug\NetSetup.log (a diagnostic file used for troubleshooting domain join issues) together with process-list output

WebSocket Tunnelers: BridgeHead and ArcBridge

Two other malware families delivered as part of the attacks are BridgeHead ("unbcl.dll"), a SOCKS5 tunnel proxy observed in environments in Egypt and Pakistan that shares some level of functional overlaps with MiniFast (aka MiniUpdate and Retrograde), and ArcBridge, another WebSocket tunneling tool observed in April 2026 in activity targeting victims in the Middle East.

"The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel," the researchers said about BridgeHead. "This makes it a relay node: the operator runs tools server-side, and all resulting TCP traffic is tunneled through the victim's machine as if originating from the victim's network."

The use of BridgeHead and ArcBridge indicates the threat actor's continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND.

Related: HOLLOWGRAPH and Cavern Manticore

The disclosure comes days after Group-IB uncovered a new malware sample codenamed HOLLOWGRAPH that's linked to the Cavern (aka Cav3rn) framework used by an Iranian hacking crew dubbed Cavern Manticore.

"HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel," it said. "Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner's attention, every event is dated far into the future - 13 May 2050 - with payloads attached as files to the event."

Comments

No comments yet. Start the discussion.