Close Menu
    What's Hot

    Only one ‘Magnificent 7’ stock is having a truly magnificent year. The reason may surprise you

    Putin Will Escalate

    Live Updates: Many Feared Trapped in Mall Collapse After Japan Earthquake, Officials Say

    Facebook X (Twitter) Instagram
    Trending
    • Only one ‘Magnificent 7’ stock is having a truly magnificent year. The reason may surprise you
    • Putin Will Escalate
    • Live Updates: Many Feared Trapped in Mall Collapse After Japan Earthquake, Officials Say
    • AI boom raises risks of monetary policy mistakes, warn BIS economists
    • How China’s grip on electrification metals could affect inflation
    • Silicon Valley’s Next IPO Billionaires Are Coming. Nonprofits Are Ready for Them
    • Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
    • Beyond Amsterdam and Venice: 6 Delightful European Canal Cities
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

    adminBy adminJuly 28, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 28, 2026Malware / Cyber Espionage

    Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

    The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.

    The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

    Targets of the campaign include Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso, per Kaspersky.

    “The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling,” Kaspersky researchers Omar Amin and Vasily Berdnikov said.

    The exact initial access method used in the attacks is presently unknown, although the adversary is known to employ highly tailored job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect recipients to malicious archives hosted on third-party file-sharing services.

    Cybersecurity

    The as-yet-undetermined access route is then abused to deliver the malicious payloads, including NightLedger, which is launched as a DLL via DLL side-loading. The malware is designed to contact an external server over HTTPS to parse and run commands in a manner that’s analogous to TWOSTROKE, another backdoor deployed by the threat actor in the past. The list of supported commands is below –

    • Gather user and host identity information
    • Execute a process/program
    • List directories
    • Download a file to the infected system
    • Collect host and network information
    • Copy or delete files
    • Update beacon interval
    • Take a screenshot
    • Load a DLL
    • Terminate a process or thread
    • Upload file to the command-and-control (C2) server via an HTTP POST request
    • Enumerate logical drives
    • List processes
    • Collect C:\Windows\debug\NetSetup.log (a diagnostic file used for troubleshooting domain join issues) together with process-list output

    Two other malware families delivered as part of the attacks are BridgeHead (“unbcl.dll”), a SOCKS5 tunnel proxy observed in environments in Egypt and Pakistan that shares some level of functional overlaps with MiniFast (aka MiniUpdate and Retrograde), and ArcBridge, another WebSocket tunneling tool observed in April 2026 in activity targeting victims in the Middle East.

    “The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel,” the researchers said about BridgeHead. “This makes it a relay node: the operator runs tools server-side, and all resulting TCP traffic is tunneled through the victim’s machine as if originating from the victim’s network.”

    Cybersecurity

    The use of BridgeHead and ArcBridge indicates the threat actor’s continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND.

    The disclosure comes days after Group-IB uncovered a new malware sample codenamed HOLLOWGRAPH that’s linked to the Cavern (aka Cav3rn) framework used by an Iranian hacking crew dubbed Cavern Manticore.

    “HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel,” it said.

    “Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner’s attention, every event is dated far into the future – 13 May 2050 – with payloads attached as files to the event.”

    covert deploys Manticore NightLedger Nimbus relays systems turns victim
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleBeyond Amsterdam and Venice: 6 Delightful European Canal Cities
    Next Article Silicon Valley’s Next IPO Billionaires Are Coming. Nonprofits Are Ready for Them
    admin
    • Website

    Related Posts

    Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

    July 28, 2026

    Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

    July 28, 2026

    Microsoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the Cost

    July 28, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Only one ‘Magnificent 7’ stock is having a truly magnificent year. The reason may surprise you

    Putin Will Escalate

    Live Updates: Many Feared Trapped in Mall Collapse After Japan Earthquake, Officials Say

    AI boom raises risks of monetary policy mistakes, warn BIS economists

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by