


Perceptive Security
SOC/SIEM Consultancy

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Published:
28 juli 2026 om 11:55:20
Alert date:
28 juli 2026 om 13:00:52
Source:
thehackernews.com
Ransomware & Malware, Network Infrastructure, Critical Infrastructure, Data Breach & Exfiltration
The Iranian state-sponsored threat group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to a new wave of cyberattacks targeting organizations across the Middle East, Africa, and South Asia. The campaign introduces a previously undocumented Windows backdoor named NightLedger, alongside two custom WebSocket tunnelers used to establish covert communication channels. Victim systems are being repurposed as covert relay nodes, likely to obfuscate attacker infrastructure and complicate attribution. The group is known for its persistent targeting of defense, aerospace, and government sectors. This activity reflects continued Iranian cyber espionage efforts in strategically sensitive regions. The use of custom tooling such as NightLedger indicates significant development investment by the threat actor. The dual WebSocket tunnelers suggest a layered approach to maintaining stealthy, persistent access within compromised environments.
Technical details
Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, UNC1549), an Iranian state-backed hacking group, has deployed a previously undocumented Windows backdoor called NightLedger alongside two custom WebSocket tunnelers, BridgeHead and ArcBridge, in attacks targeting entities across the Middle East, Africa, and South Asia. NightLedger is loaded as a DLL via DLL side-loading and communicates with an external C2 server over HTTPS to parse and execute commands, functioning similarly to the group's previously used TWOSTROKE backdoor. Its capabilities include gathering user and host identity information, executing processes/programs, listing directories, downloading/uploading files, collecting host and network information, copying/deleting files, updating beacon intervals, taking screenshots, loading DLLs, terminating processes/threads, enumerating logical drives, listing processes, and collecting C:\Windows\debug\NetSetup.log with process-list output. BridgeHead (unbcl.dll) is a SOCKS5 tunnel proxy observed in Egypt and Pakistan environments, sharing functional overlaps with MiniFast (aka MiniUpdate, Retrograde). It operates by having the C2 server initiate all tunnel connections via binary commands over WebSocket, turning victim systems into relay nodes where the operator runs tools server-side and all resulting TCP traffic is tunneled through the victim's machine. ArcBridge is another WebSocket tunneling tool observed in April 2026 targeting victims in the Middle East. Initial access method is unknown, but the group is known to use job opportunity-themed phishing lures impersonating trusted brands and hiring platforms, as well as lookalike videoconferencing pages, redirecting victims to malicious archives on third-party file-sharing services. Targeted sectors include government, aviation, telecommunications, financial services, and SMBs across Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The disclosure also references a related Iranian threat actor (Cavern Manticore) using HOLLOWGRAPH malware, which abuses the Microsoft Graph API to use a compromised Microsoft 365 calendar as a covert two-way C2 channel, with operators planting tasks as calendar events dated to 13 May 2050 and exfiltrating data as encrypted attachments.
Mitigation steps:
1. Monitor for suspicious DLL side-loading activity on Windows systems, particularly unexpected DLL loads by legitimate applications. 2. Inspect outbound HTTPS traffic for anomalous C2 beacon patterns consistent with NightLedger behavior. 3. Monitor for unexpected WebSocket tunneling traffic (BridgeHead, ArcBridge) that may indicate relay node activity. 4. Review and alert on access to C:\Windows\debug\NetSetup.log by unauthorized processes. 5. Implement email and web filtering to detect and block job opportunity-themed phishing lures and lookalike videoconferencing pages. 6. Block or monitor downloads of archives from third-party file-sharing services in sensitive environments. 7. Monitor Microsoft 365 calendar events for anomalies such as events dated far into the future (e.g., 2050) with file attachments. 8. Audit Microsoft Graph API access and permissions for signs of HOLLOWGRAPH-type abuse. 9. Hunt for the filename unbcl.dll on endpoints as a specific IOC for BridgeHead. 10. Implement network segmentation to limit the ability of compromised systems to act as relay nodes. 11. Leverage threat intelligence on Nimbus Manticore/UNC1549 TTPs to tune SIEM and EDR detections.
Affected products:
Windows (DLL side-loading vector)
Microsoft 365 (Calendar/Graph API abused by HOLLOWGRAPH)
Related links:
https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html
https://securelist.com/mirage-kitten-new-tools/120811/
https://thehackernews.com/2025/11/iranian-hackers-use-deeproot-and.html
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
https://thehackernews.com/2026/07/iran-linked-hackers-use-new-cavern-c2.html
Related CVE's:
Related threat actors:
IOC's:
NightLedger - Windows backdoor DLL (loaded via DLL side-loading), BridgeHead - SOCKS5 tunnel proxy DLL filename: unbcl.dll, ArcBridge - WebSocket tunneling tool, HOLLOWGRAPH - malware abusing Microsoft Graph API for C2 via calendar events, C2 communication over HTTPS (NightLedger), WebSocket-based tunneling (BridgeHead, ArcBridge), Calendar events dated 13 May 2050 with encrypted attachments (HOLLOWGRAPH IOC), Collection of C:\Windows\debug\NetSetup.log, Job opportunity-themed phishing lures and lookalike videoconferencing pages, Malicious archives hosted on third-party file-sharing services
This article was created with the assistance of AI technology by Perceptive.
