DEV Community

Mark0
Mark0

Posted on

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

⚠️ Region Alert: UAE/Middle East

The Iranian state-backed threat actor Nimbus Manticore (also known as Mirage Kitten or Smoke Sandstorm) has launched a new series of cyberattacks targeting government, aviation, and financial sectors across the Middle East, Africa, and South Asia. The campaign features a previously undocumented Windows backdoor named NightLedger, alongside custom WebSocket-based tunnelers called BridgeHead and ArcBridge. These tools are designed to provide the attackers with persistent, covert network access and the ability to execute remote commands, capture screenshots, and exfiltrate sensitive files.

Initial access is often achieved through highly tailored phishing campaigns that use job-themed lures or lookalike videoconferencing pages to deliver malicious payloads via DLL side-loading. NightLedger acts as a primary backdoor for reconnaissance and command execution, while the tunneling utilities allow the operators to route TCP traffic through compromised machines, effectively turning them into relay nodes. Additionally, researchers have identified a separate malware called HOLLOWGRAPH, which abuses the Microsoft Graph API to turn Microsoft 365 calendars into a covert command-and-control channel.


Read Full Article

Top comments (0)