VMTech
+381 11 4183 54024/7 Discuss a project

Nimbus Manticore Uses NightLedger and WebSocket Tunnels to Build Covert Relays

Nimbus Manticore Uses NightLedger and WebSocket Tunnels to Build Covert Relays

On July 28, 2026, Kaspersky detailed a campaign by the Iranian state-backed group Nimbus Manticore, also tracked as UNC1549, involving the previously undocumented Windows backdoor NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge.

Why covert relays increase the risk

Targets span Egypt; SMB and government environments in Jordan and Tanzania; aviation organizations in Pakistan; telecom companies in Ethiopia; and financial entities in Burkina Faso. The initial access method remains unknown, although the group has previously used tailored job-themed phishing, brand impersonation, and lookalike videoconferencing pages.

The tunnelers turn infected systems into operator-controlled gateways. Traffic can appear to originate within the victim’s network, making malicious activity harder to trace and giving server-side tools a route towards internal targets.

How the toolset operates

NightLedger is launched through DLL side-loading and communicates with an external server over HTTPS. It supports reconnaissance, process and drive enumeration, command execution, file transfer, DLL loading, screenshots, beacon updates, and collection of C:\Windows\debug\NetSetup.log. Its command handling resembles the earlier TWOSTROKE backdoor.

“The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel,” Kaspersky researchers Omar Amin and Vasily Berdnikov said of BridgeHead.

BridgeHead, observed as “unbcl.dll” in Egypt and Pakistan, is a SOCKS5 tunnel proxy with functional overlaps with MiniFast. ArcBridge appeared in April 2026 activity targeting Middle Eastern victims. The group previously deployed bespoke tunnelers LIGHTRAIL and POLLBLEND.

Separately, Group-IB linked HOLLOWGRAPH to Cavern Manticore. The malware uses Microsoft Graph API and a compromised Microsoft 365 calendar as a two-way C2 channel, placing tasks and encrypted stolen files in events dated May 13, 2050.

Businesses should monitor unusual DLL loading, outbound HTTPS and WebSocket sessions, SOCKS-like relay behavior, and anomalous Microsoft 365 calendar activity. A compromised endpoint may become trusted infrastructure for deeper intrusion, not merely a source of data loss.

#cybersecurity#malware#threatintel#windows
Current metrics
0Views
0Reach
0Likes
0Comments
0Saved
0Shares
Instagram

Nimbus Manticore Uses NightLedger and WebSocket Tunnels to Build Covert Relays

Open the post on Instagram ↗