Threat Intelligence
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
Cyber RTJuly 28, 20263 min read

The Iranian hacking group Nimbus Manticore is targeting entities in the Middle East, Africa, and South Asia using a new Windows backdoor called NightLedger and custom WebSocket tunnelers, BridgeHead and ArcBridge, for covert access. Targets include sectors in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The group uses phishing lures for initial access, delivering malware to execute commands and exfiltrate data.
The Iranian state-backed hacking group known as Nimbus Manticore, also referred to by several aliases such as GalaxyGato and Smoke Sandstorm, has been linked to a new wave of cyberattacks targeting various regions including the Middle East, Africa, and South Asia. These attacks utilize a newly identified Windows backdoor named NightLedger, alongside two custom WebSocket tunnelers, BridgeHead and ArcBridge, to maintain stealthy access to compromised systems. The campaign specifically targets entities in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, affecting sectors such as government, telecommunications, aviation, and finance.
The attack toolkit employed by Nimbus Manticore includes NightLedger, which is a Windows backdoor used for reconnaissance and executing commands, and two WebSocket-based tunnelers, ArcBridge and BridgeHead, which facilitate covert network access. These tools enable the attackers to perform various operations such as file manipulation, process discovery, and screenshot capture, while maintaining a hidden presence in the victim's network.
The initial method of gaining access to the targeted systems remains unclear. However, the group is known for using sophisticated phishing techniques, including job opportunity-themed lures that mimic trusted brands and videoconferencing platforms. These lures redirect victims to malicious archives hosted on third-party file-sharing services, setting the stage for the deployment of the NightLedger malware.
Once access is obtained, the NightLedger backdoor is deployed via DLL side-loading. This malware communicates with an external server over HTTPS to execute a range of commands similar to those used by TWOSTROKE, another backdoor previously used by the group. The commands supported by NightLedger include gathering system information, executing programs, managing files, and uploading data to a command-and-control server.
In addition to NightLedger, the attacks also involve the deployment of BridgeHead and ArcBridge, which are tunneling tools that facilitate covert communication between the compromised systems and the attackers' servers. BridgeHead acts as a SOCKS5 tunnel proxy, while ArcBridge serves as a WebSocket tunneling tool, both enabling the attackers to route traffic through the victim's network as if it originated locally.
The continued use of tunneling utilities by Nimbus Manticore, such as BridgeHead and ArcBridge, highlights their reliance on bespoke tools for maintaining covert operations. This approach has been observed in previous campaigns where the group used similar utilities like LIGHTRAIL and POLLBLEND to achieve their objectives.
The revelation of these attacks coincides with the discovery of a new malware sample named HOLLOWGRAPH by Group-IB. This malware is linked to the Cavern framework used by another Iranian hacking group known as Cavern Manticore. HOLLOWGRAPH exploits the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert command-and-control channel, using calendar events to exfiltrate data without alerting the mailbox owner.
In conclusion, the activities of Nimbus Manticore and the newly discovered HOLLOWGRAPH malware underscore the persistent threat posed by Iranian state-backed hacking groups. Their use of sophisticated tools and techniques to target critical sectors across multiple regions highlights the need for robust cybersecurity measures to protect against such advanced threats.


