Micron Document

► Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Source: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html
Method: legacy
Fetched: 2026-07-30T04:50:29.832919+00:00

IPFS: QmNQTitopAeX4BHEBRzR... | Open Raw
Cache: Freshly fetched


Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

The Iranian state-backed hacking group tracked asNimbus Manticore(aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

Targets of the campaign include Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso, per Kaspersky.

"The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling," Kaspersky researchers Omar Amin and Vasily Berdnikovsaid.

The exact initial access method used in the attacks is presently unknown, although the adversary is known to employ highly tailored job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect recipients to malicious archives hosted on third-party file-sharing services.

The as-yet-undetermined access route is then abused to deliver the malicious payloads, including NightLedger, which is launched as a DLL via DLL side-loading. The malware is designed to contact an external server over HTTPS to parse and run commands in a manner that's analogous toTWOSTROKE, another backdoor deployed by the threat actor in the past. The list of supported commands is below -

Two other malware families delivered as part of the attacks are BridgeHead ("unbcl.dll"), a SOCKS5 tunnel proxy observed in environments in Egypt and Pakistan that shares some level of functional overlaps withMiniFast(aka MiniUpdate and Retrograde), and ArcBridge, another WebSocket tunneling tool observed in April 2026 in activity targeting victims in the Middle East.

"The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel," the researchers said about BridgeHead. "This makes it a relay node: the operator runs tools server-side, and all resulting TCP traffic is tunneled through the victim's machine as if originating from the victim's network."

The use of BridgeHead and ArcBridge indicates the threat actor's continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such asLIGHTRAIL and POLLBLEND.

The disclosure comes days after Group-IB uncovered a new malware sample codenamedHOLLOWGRAPHthat's linked to the Cavern (aka Cav3rn) framework used by an Iranian hacking crew dubbedCavern Manticore.

"HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel," it said.

"Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner's attention, every event is dated far into the future - 13 May 2050 - with payloads attached as files to the event."

Cybersecurity Webinars

How to Secure AI Code Before It Reaches Production

Learn how 300 enterprise leaders are managing AI-driven open-source risk, remediation debt, and governance at scale.

How to Secure AI-Built Software at Machine Speed

Learn how to govern risk, secure AI-built software, and keep control as development moves at machine speed.

A Look Inside Lasso's AI Security Platform

Claude Runs Across Six Surfaces in Your Company. Your Security Team Sees One.

How to Make Social Engineering Unprofitable

The New Insider Has No Pulse: Securing Privilege When the Actor Is an AI Agent

Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free.

--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------