Nimbus Manticore unveils its new toolkit: NightLedger, BridgeHead, and ArcBridge

Iranian APT Nimbus Manticore unveils a new toolkit featuring NightLedger, BridgeHead, and ArcBridge, targeting entities in the Middle East and Africa.

Nimbus Manticore unveils its new toolkit: NightLedger, BridgeHead, and ArcBridge
APT

Illustrative image generated with AI

Introduction

On July 28, 2026, a threat intelligence report shed light on a new offensive campaign conducted by the Iranian APT group Nimbus Manticore, also known as GalaxyGato, Mirage Kitten, or UNC1549. The operation, still ongoing, has targeted government entities and private companies in the Middle East, Africa, and South Asia, focusing on critical sectors such as public administration in Jordan and Tanzania, the aviation industry in Pakistan, telecommunications in Ethiopia, finance in Burkina Faso, and sensitive targets in Egypt. The peculiarity of this campaign lies in the introduction of three previously unseen malicious tools – NightLedger, BridgeHead, and ArcBridge – which significantly expand the group's espionage and lateral movement capabilities.

Technical Analysis

The new tools demonstrate an evolution in the attacker's techniques, reinforcing their historic preference for modular backdoors and custom tunnelers.

NightLedger is a Windows backdoor distributed as a DLL. It uses DLL side-loading to be loaded into legitimate processes, a technique already adopted by the group with the previous TWOSTROKE backdoor. Once active, it communicates with the command-and-control (C2) server over HTTPS, evading superficial network inspections. Its capabilities include system reconnaissance (collecting machine and network information), executing arbitrary commands, file management, taking screenshots, and enumerating processes and disk drives. It is a comprehensive tool for maintaining persistent and covert access.

BridgeHead is a SOCKS5 proxy implemented as a DLL (unbcl.dll). It turns the infected system into a relay node: the operator sends commands through a WebSocket channel from the C2, and all subsequent TCP traffic passes through the victim machine. This allows attackers to mask their malicious communications as if they originated from the victim's legitimate network, bypassing firewall policies and geolocation-based detection.

ArcBridge is another WebSocket-based tunneler, first observed in April 2026 in the Middle East. It shares with BridgeHead the goal of creating hard-to-detect communication channels, contributing to persistence and operational flexibility.

The initial infection vector has not been confirmed, but Nimbus Manticore is known for highly targeted spear-phishing campaigns: fake job offers, counterfeit videoconference invitations, and malicious archives distributed via file-sharing services. The use of side-loading indicates that the attacker already requires some level of access or relies on techniques to trick the user into executing malicious executables.

In a parallel context, another Iranian group, Cavern Manticore, has recently employed the HOLLOWGRAPH malware, which abuses Microsoft Graph APIs to turn a Microsoft 365 calendar into a bidirectional C2 channel. Events set for May 13, 2050 serve as containers for commands and exfiltrated data. Although a distinct operation, it demonstrates the ingenuity of Iranian actors in leveraging trusted cloud services to evade detection.

Impact

The severity of the threat is high. This is a nation-state actor with advanced capabilities, focused on government infrastructure and strategic sectors. The use of NightLedger gives attackers prolonged covert access, enabling exfiltration of sensitive data, continuous surveillance, and preparation for more destructive operations. BridgeHead and ArcBridge allow turning victims into relay nodes, masking the geographical origin of attacks and facilitating lateral movement within compromised networks. The abuse of cloud APIs, as seen with HOLLOWGRAPH, further expands the possibilities for stealthy exfiltration.

Mitigation

Although no specific mitigations for this campaign have been provided, recommended defenses include:

  • Anti-phishing training: raise awareness among users, especially those in sensitive areas, to recognize recruitment-themed lures or fake videoconferencing services.
  • Code execution controls: monitor and restrict the side-loading of unsigned DLLs, enable AppLocker or Windows Defender Application Control.
  • Network traffic inspection: analyze WebSocket traffic to unusual destinations and block unauthorized SOCKS5 connections at the proxy level.
  • Segmentation and least privilege: segment networks to hinder lateral movement and apply the principle of least privilege on endpoints.
  • Microsoft Graph monitoring: check for anomalous accesses to Graph APIs, especially on non-administrator user calendars, and implement Conditional Access policies.

FAQ

1. Who is Nimbus Manticore and what targets does it hit?

Nimbus Manticore is an Iranian APT (Advanced Persistent Threat) group, also known by various aliases such as GalaxyGato, Mirage Kitten, and UNC1549. It focuses on espionage and cyber operations against governments, critical infrastructure, and companies in the Middle East, Africa, and Asia. Sectors targeted include public administration, defense, aerospace, telecommunications, and finance.

2. How do the new tools NightLedger and BridgeHead operate?

NightLedger is a DLL backdoor that uses DLL side-loading to infect legitimate Windows processes. It communicates over HTTPS and allows the attacker to execute commands, steal files, take screenshots, and gather system information. BridgeHead is a SOCKS5 proxy that turns the infected machine into a relay: it receives instructions via WebSocket and routes the operator's traffic through the victim, hiding the attacker's real infrastructure.

3. What immediate measures can organizations take to protect themselves?

Priorities include: strengthening staff training against phishing, especially messages promising job offers or meeting links; implementing strict controls on DLL and script execution; monitoring WebSocket traffic and blocking non-essential SOCKS5 relays; segmenting the network; and carefully monitoring Microsoft Graph API accesses to detect any abuse similar to HOLLOWGRAPH.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →