{"id":2042,"date":"2026-07-28T13:43:03","date_gmt":"2026-07-28T13:43:03","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2042"},"modified":"2026-07-28T13:43:03","modified_gmt":"2026-07-28T13:43:03","slug":"nimbus-manticore-deploys-nightledger-and-turns-victim-systems-into-covert-relays","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2042","title":{"rendered":"Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 28, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ Cyber Espionage<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh-Whbx97t7xBrrpM26fYSbwg29hdKR8zskNLIwlrWC0Jd3Rrf4INhiCTI3WMw8NzmJ1iETQlt-CKdUxBzL2hef4pgQBOoI1rrrtRbU96hJRUXtTGy5dT40mP2B1AshyphenhyphenM4mc1K1-IISWwY6PSPyGXNBHplHM8kuxX9e5Di6RmMybyO2Q7Guu__CK8jOOkja\/s1700-e365\/proxy.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The Iranian state-backed hacking group tracked as <strong>Nimbus Manticore<\/strong> (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.<\/p>\n<p>The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.<\/p>\n<p>Targets of the campaign include Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso, per Kaspersky.<\/p>\n<p>\u00abThe toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling,\u00bb Kaspersky researchers Omar Amin and Vasily Berdnikov <a href=\"https:\/\/securelist.com\/mirage-kitten-new-tools\/120811\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>The exact initial access method used in the attacks is presently unknown, although the adversary is known to employ highly tailored job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect recipients to malicious archives hosted on third-party file-sharing services.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The as-yet-undetermined access route is then abused to deliver the malicious payloads, including NightLedger, which is launched as a DLL via DLL side-loading. The malware is designed to contact an external server over HTTPS to parse and run commands in a manner that&#8217;s analogous to TWOSTROKE, another backdoor deployed by the threat actor in the past. The list of supported commands is below &#8211;<\/p>\n<ul>\n<li>Gather user and host identity information<\/li>\n<li>Execute a process\/program<\/li>\n<li>List directories<\/li>\n<li>Download a file to the infected system<\/li>\n<li>Collect host and network information<\/li>\n<li>Copy or delete files<\/li>\n<li>Update beacon interval<\/li>\n<li>Take a screenshot<\/li>\n<li>Load a DLL<\/li>\n<li>Terminate a process or thread<\/li>\n<li>Upload file to the command-and-control (C2) server via an HTTP POST request<\/li>\n<li>Enumerate logical drives<\/li>\n<li>List processes<\/li>\n<li>Collect C:\\Windows\\debug\\NetSetup.log (a diagnostic file used for troubleshooting domain join issues) together with process-list output<\/li>\n<\/ul>\n<p>Two other malware families delivered as part of the attacks are BridgeHead (\u00abunbcl.dll\u00bb), a SOCKS5 tunnel proxy observed in environments in Egypt and Pakistan that shares some level of functional overlaps with <a href=\"https:\/\/thehackernews.com\/2026\/05\/iranian-hackers-deploy-minifast-and.html\" target=\"_blank\">MiniFast (aka MiniUpdate and Retrograde), and ArcBridge, another WebSocket tunneling tool observed in April 2026 in activity targeting victims in the Middle East.<\/p>\n<p>\u00abThe C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel,\u00bb the researchers said about BridgeHead. \u00abThis makes it a relay node: the operator runs tools server-side, and all resulting TCP traffic is tunneled through the victim&#8217;s machine as if originating from the victim&#8217;s network.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjnP2BIJTKZ31v-Y_pyvFqC1s6LD-Bo8UNy3UHgqojpVezgaGWw5-sPe5uRK0dfSm3gmDvoKCdHoJnGx1BiTP6Y0qit7D7TCZU_LckTDpdu9eeyuelmJKndEkOxZP6oNPwzguLBCTkAnNkIEvSYaWamKLqYLrJPjnea1V_lz7UcfQkavBo2g3OEGoLyz7mD\/s728-e100\/sygnia-d-4.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The use of BridgeHead and ArcBridge indicates the threat actor&#8217;s continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND.<\/p>\n<p>The disclosure comes days after Group-IB uncovered a new malware sample codenamed HOLLOWGRAPH that&#8217;s linked to the Cavern (aka Cav3rn) framework used by an Iranian hacking crew dubbed Cavern Manticore.<\/p>\n<p>\u00abHOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel,\u00bb it said.<\/p>\n<p>\u00abUsing the Microsoft Graph API, it treats the compromised mailbox&#8217;s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner&#8217;s attention, every event is dated far into the future &#8211; 13 May 2050 &#8211; with payloads attached as files to the event.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 28, 2026Malware \/ Cyber Espionage The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2043,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1921,297,2758,2759,2757,2094,224,521,2729],"class_list":["post-2042","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-covert","tag-deploys","tag-manticore","tag-nightledger","tag-nimbus","tag-relays","tag-systems","tag-turns","tag-victim"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2042","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2042"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2042\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2043"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2042"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2042"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2042"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}