The Iranian state-backed hacking group known as Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, and Subtle Snail) has launched a new series of attacks. These intrusions are targeting various entities across the Middle East, Africa, and South Asia, including government, aviation, telecommunication, and financial organizations.
The campaign utilizes a previously undocumented Windows backdoor named NightLedger. Additionally, the attackers are deploying two custom WebSocket tunnelers, BridgeHead and ArcBridge. These tools are designed to establish and maintain covert access to victim systems.
NightLedger functions as a backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture. BridgeHead and ArcBridge facilitate covert network access and operator-controlled tunneling.
Kaspersky reports that the targets include organizations in Egypt, SMBs and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso.
The exact initial access method for these specific attacks remains unknown. However, Nimbus Manticore has previously used highly tailored phishing lures, often disguised as job opportunities or lookalike videoconferencing pages, to redirect victims to malicious archives hosted on third-party file-sharing services. The malicious payloads, including NightLedger, are then delivered, often launched as a DLL via DLL side-loading.
NightLedger communicates with an external server over HTTPS to parse and execute commands, similar to the group's previous TWOSTROKE backdoor. Its capabilities include gathering user and host identity, executing processes, listing directories, downloading/uploading files, collecting host and network information, copying/deleting files, updating beacon intervals, taking screenshots, loading DLLs, terminating processes, and enumerating logical drives.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Iranian state-backed hacking group Nimbus Manticore is using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, in recent attacks targeting organizations across the Middle East, Africa, and South Asia. These tools allow the group to maintain covert access and conduct reconnaissance, command execution, and data exfiltration on compromised systems.