Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

August 2, 2026

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

August 2, 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

August 2, 2026
Facebook X (Twitter) Instagram
Monday, August 3
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
News

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Team-CWDBy Team-CWDAugust 2, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

Targets of the campaign include Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso, per Kaspersky.

“The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling,” Kaspersky researchers Omar Amin and Vasily Berdnikov said.

The exact initial access method used in the attacks is presently unknown, although the adversary is known to employ highly tailored job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect recipients to malicious archives hosted on third-party file-sharing services.

The as-yet-undetermined access route is then abused to deliver the malicious payloads, including NightLedger, which is launched as a DLL via DLL side-loading. The malware is designed to contact an external server over HTTPS to parse and run commands in a manner that’s analogous to TWOSTROKE, another backdoor deployed by the threat actor in the past. The list of supported commands is below –

  • Gather user and host identity information
  • Execute a process/program
  • List directories
  • Download a file to the infected system
  • Collect host and network information
  • Copy or delete files
  • Update beacon interval
  • Take a screenshot
  • Load a DLL
  • Terminate a process or thread
  • Upload file to the command-and-control (C2) server via an HTTP POST request
  • Enumerate logical drives
  • List processes
  • Collect C:WindowsdebugNetSetup.log (a diagnostic file used for troubleshooting domain join issues) together with process-list output

Two other malware families delivered as part of the attacks are BridgeHead (“unbcl.dll”), a SOCKS5 tunnel proxy observed in environments in Egypt and Pakistan that shares some level of functional overlaps with MiniFast (aka MiniUpdate and Retrograde), and ArcBridge, another WebSocket tunneling tool observed in April 2026 in activity targeting victims in the Middle East.

“The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel,” the researchers said about BridgeHead. “This makes it a relay node: the operator runs tools server-side, and all resulting TCP traffic is tunneled through the victim’s machine as if originating from the victim’s network.”

The use of BridgeHead and ArcBridge indicates the threat actor’s continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND.

The disclosure comes days after Group-IB uncovered a new malware sample codenamed HOLLOWGRAPH that’s linked to the Cavern (aka Cav3rn) framework used by an Iranian hacking crew dubbed Cavern Manticore.

“HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel,” it said.

“Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner’s attention, every event is dated far into the future – 13 May 2050 – with payloads attached as files to the event.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Team-CWD
  • Website

Related Posts

News

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

August 2, 2026
News

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

August 2, 2026
News

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

August 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What it takes to fool facial recognition

March 14, 2026

Common Apple Pay scams, and how to stay safe

January 22, 2026

Watch out for SVG files booby-trapped with malware

September 22, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.