Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Kaspersky attributes a fresh wave of attacks across the Middle East, Africa, and South Asia to Iranian group Nimbus Manticore, which deployed a new Windows backdoor called NightLedger alongside custom WebSocket tunnelers BridgeHead and ArcBridge to covertly relay traffic …
Intelligence analysis by Llama

Iranian APT Nimbus Manticore is targeting entities in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso with a never-before-seen Windows backdoor called NightLedger and two WebSocket tunneling tools. The toolkit turns compromised hosts into operator-controlled relays, enabling covert network access across high-value sectors.
Imagine a spy sneaking into a building and then turning the building itself into a secret telephone switchboard, so other spies can make calls from inside without anyone noticing. That's what Nimbus Manticore is doing with its new NightLedger tool: it slips into computers, then uses those computers to secretly pass messages between the bad guys and other targets.
Analysis
NightLedger Reshapes Nimbus Manticore's Post-Exploitation Playbook
Kaspersky researchers Omar Amin and Vasily Berdnikov have lifted the lid on a previously undocumented Windows backdoor called NightLedger, which they say is central to a new campaign attributed with high confidence to the Iranian state-backed cluster Nimbus Manticore. The implant is launched as a DLL via DLL side-loading and reaches out to an external server over HTTPS to parse and execute commands, a pattern the researchers describe as analogous to TWOSTROKE, another backdoor the group has used historically. The supported command set covers the usual espionage basics: user and host enumeration, process discovery, file upload and download, screenshot capture, and beacon-interval updates, plus a curious grab of the NetSetup.log diagnostic file alongside an active process list, a combination that suggests the operators are specifically fingerprinting domain-join troubleshooting artifacts.
Turned Hosts Into Relay Nodes
What elevates this campaign beyond a conventional backdoor deployment is the pairing of NightLedger with two custom WebSocket-based tunnelers, BridgeHead and ArcBridge. BridgeHead, observed in environments in Egypt and Pakistan, functions as a SOCKS5 proxy with functional overlap to the group's earlier MiniFast (also known as MiniUpdate and Retrograde) tool. ArcBridge, another WebSocket tunneling utility, was first seen in April 2026 in activity targeting Middle East victims. According to Kaspersky, the C2 server initiates all tunnel connections by sending binary commands over the WebSocket, and the implant simply forwards traffic between server-specified targets and the WebSocket channel. The practical effect is that the operator runs tools server-side and all resulting TCP traffic is tunneled through the victim's machine as if originating from the victim's network, effectively converting compromised hosts into covert relays for follow-on operations against harder-to-reach assets.
A Broader Iranian Toolkit Is Coming Into Focus
The Nimbus Manticore activity lands just days after Group-IB disclosed a separate piece of tradecraft, HOLLOWGRAPH, tied to the Cavern framework used by a related Iranian actor called Cavern Manticore. HOLLOWGRAPH abuses the Microsoft Graph API to turn a compromised Microsoft 365 calendar into a two-way dead-drop channel, with operators planting tasking as calendar events and the implant exfiltrating stolen files by creating its own events with encrypted data attached, all dated far into the future to avoid alerting the mailbox owner. Taken together, the two disclosures paint a picture of an Iranian ecosystem that is investing heavily in living-off-cloud-services and bespoke tunneling utilities to maintain stealthy access across Middle Eastern, African, and South Asian targets. The initial access vector for the NightLedger wave remains undisclosed, but the group is known to lean on highly tailored job-opportunity phishing lures and lookalike videoconferencing pages that deliver malicious archives from third-party file-sharing services, a reminder that identity-aware phishing defenses remain a frontline control for the aviation, telecom, and financial entities now in the crosshairs.
Key points
- Iranian APT Nimbus Manticore is using a previously unseen Windows backdoor called NightLedger alongside custom WebSocket tunnelers BridgeHead and ArcBridge.
- Targets span Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aviation, telecom, government, SMB, and financial sectors.
- BridgeHead and ArcBridge turn compromised hosts into relay nodes, letting operators tunnel TCP traffic through victim networks as if it originated locally.
- The initial access method is still unknown, but Nimbus Manticore is known for tailored job-opportunity phishing lures and lookalike videoconferencing pages.
- The disclosure follows Group-IB's report on HOLLOWGRAPH, a related Iranian tool that abuses Microsoft Graph API calendars as a covert C2 channel.
If the campaign scales as the geographic spread suggests, organizations in aviation, telecom, government, and financial services across the Middle East, Africa, and South Asia face a heightened risk of lateral movement powered by the BridgeHead and ArcBridge relays. The undisclosed initial access vector and the group's history of convincing job-themed phishing lures mean defenders cannot yet reliably block the entry point, and the WebSocket tunneling traffic is likely to blend in with legitimate enterprise communications.


