← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Nimbus Manticore Deploys New NightLedger Backdoor and WebSocket Tunnelers in Attacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Nimbus Manticore uses NightLedger backdoor and BridgeHead/ArcBridge tunnelers.
  • Targets include government, aviation, telecom, and financial sectors.
  • NightLedger performs reconnaissance, command execution, and file operations.
  • Initial access method is currently unknown.

New Attack Campaign Uncovered

The Iranian state-backed hacking group known as Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, and Subtle Snail) has launched a new series of attacks. These intrusions are targeting various entities across the Middle East, Africa, and South Asia, including government, aviation, telecommunication, and financial organizations.

New Malware Tools Identified

The campaign utilizes a previously undocumented Windows backdoor named NightLedger. Additionally, the attackers are deploying two custom WebSocket tunnelers, BridgeHead and ArcBridge. These tools are designed to establish and maintain covert access to victim systems.

NightLedger functions as a backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture. BridgeHead and ArcBridge facilitate covert network access and operator-controlled tunneling.

Targeted Regions and Sectors

Kaspersky reports that the targets include organizations in Egypt, SMBs and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso.

Initial Access Methods

The exact initial access method for these specific attacks remains unknown. However, Nimbus Manticore has previously used highly tailored phishing lures, often disguised as job opportunities or lookalike videoconferencing pages, to redirect victims to malicious archives hosted on third-party file-sharing services. The malicious payloads, including NightLedger, are then delivered, often launched as a DLL via DLL side-loading.

NightLedger Capabilities

NightLedger communicates with an external server over HTTPS to parse and execute commands, similar to the group's previous TWOSTROKE backdoor. Its capabilities include gathering user and host identity, executing processes, listing directories, downloading/uploading files, collecting host and network information, copying/deleting files, updating beacon intervals, taking screenshots, loading DLLs, terminating processes, and enumerating logical drives.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The Iranian state-backed hacking group Nimbus Manticore is using a new Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, in recent attacks targeting organizations across the Middle East, Africa, and South Asia. These tools allow the group to maintain covert access and conduct reconnaissance, command execution, and data exfiltration on compromised systems.