⚠️ Region Alert: UAE/Middle East
The Iranian threat group Nimbus Manticore (also known as Mirage Kitten or Smoke Sandstorm) has launched a new campaign targeting various sectors across the Middle East, Africa, and South Asia. The group is utilizing a newly discovered Windows backdoor named NightLedger for reconnaissance and command execution, alongside two custom WebSocket tunnelers, BridgeHead and ArcBridge, designed to facilitate covert network access and bypass security perimeters.
Furthermore, the group has been linked to the HOLLOWGRAPH malware, which demonstrates advanced persistence by abusing the Microsoft Graph API. This tool uses compromised Microsoft 365 calendars as a two-way command-and-control channel, hiding encrypted data within future calendar events. These developments signify a shift towards more sophisticated, cloud-native exfiltration techniques and bespoke tunneling tools to maintain a long-term presence in victim environments.
Top comments (0)