Iranian state-backed hacking group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to a new wave of cyber espionage attacks targeting organizations across the Middle East, Africa, and South Asia. The campaign leverages a previously undocumented Windows backdoor called NightLedger, along with two custom WebSocket tunnelers—BridgeHead and ArcBridge—to establish and maintain covert access to victim networks.
According to Kaspersky researchers Omar Amin and Vasily Berdnikov, the toolset includes NightLedger, a Windows backdoor capable of reconnaissance, command execution, file operations, process discovery, and screenshot capture. The two WebSocket-based tunnelers, ArcBridge and BridgeHead, provide covert network access and operator-controlled tunneling. Targets include Egypt, small and medium businesses and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia, and financial-sector entities in Burkina Faso.
The initial access method remains unknown, but the adversary is known to use highly tailored job opportunity-themed phishing lures that impersonate trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect victims to malicious archives hosted on third-party file-sharing services. Once access is gained, NightLedger is delivered as a DLL via DLL side-loading and communicates with an external server over HTTPS to parse and execute commands, similar to the previously observed TWOSTROKE backdoor.
BridgeHead, observed in Egypt and Pakistan, functions as a SOCKS5 tunnel proxy with functional overlaps to MiniFast (aka MiniUpdate and Retrograde). ArcBridge, another WebSocket tunneling tool, was seen in April 2026 targeting victims in the Middle East. The C2 server initiates all tunnel connections by sending binary commands over WebSocket, making the victim machine a relay node that forwards traffic as if originating from the victim’s network. This marks a continued reliance on tunneling utilities, previously including LIGHTRAIL and POLLBLEND.
Separately, Group-IB uncovered a new malware sample codenamed HOLLOWGRAPH, linked to the Cavern (Cav3rn) framework used by another Iranian hacking crew, Cavern Manticore. HOLLOWGRAPH abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel, with tasking planted as calendar events dated far into the future (e.g., May 13, 2050) to avoid detection.
CVEs: CVE-2026-50522
Attack groups: Nimbus Manticore, Cavern Manticore
Malware: NightLedger, BridgeHead, ArcBridge, TWOSTROKE, MiniFast, LIGHTRAIL, POLLBLEND, HOLLOWGRAPH
Companies: Kaspersky, Group-IB, Microsoft
Products: Microsoft 365, Microsoft Graph API
Original source: thehackernews.com