Nimbus Manticore Deploys NightLedger Backdoor in Covert Attacks

The Iranian state-sponsored hacking group known as Nimbus Manticore has launched a series of cyberattacks targeting organizations across the Middle East, Africa, and South Asia. These operations involve the deployment of a newly identified Windows backdoor named NightLedger, along with two custom WebSocket-based tunneling tools, BridgeHead and ArcBridge, designed to maintain covert access to compromised systems.

Among the affected entities are government and small-to-medium-sized businesses in Jordan and Tanzania, aviation firms in Pakistan, telecommunications companies in Ethiopia, and financial institutions in Burkina Faso. The exact methods used to gain initial access remain unclear. However, Nimbus Manticore is known for employing highly tailored phishing campaigns that mimic reputable brands and job recruitment platforms. These deceptive tactics often lead victims to malicious files hosted on third-party file-sharing services.

Once access is established, the attackers deploy NightLedger by exploiting DLL side-loading techniques. This backdoor communicates with external servers over HTTPS, enabling the execution of various commands, including:

  • Collecting user and system information
  • Executing processes or programs
  • Listing directories
  • Downloading files to the infected system
  • Gathering host and network data
  • Managing files (copying or deleting)
  • Adjusting beacon intervals
  • Capturing screenshots
  • Loading DLLs
  • Terminating processes or threads
  • Uploading files to command-and-control servers
  • Enumerating logical drives
  • Listing active processes
  • Collecting diagnostic logs

In addition to NightLedger, the attackers utilize BridgeHead and ArcBridge to establish covert network access. BridgeHead, identified as “unbcl.dll,” functions as a SOCKS5 proxy, allowing the attackers to relay traffic through the victim’s network. This tool has been observed in attacks targeting entities in Egypt and Pakistan. ArcBridge, another WebSocket tunneling tool, was detected in April 2026 during operations in the Middle East.

The use of these tunneling utilities indicates Nimbus Manticore’s ongoing efforts to develop and deploy sophisticated tools for maintaining persistent access to compromised networks. This strategy aligns with their previous use of custom tunnelers like LIGHTRAIL and POLLBLEND.

These developments underscore the evolving tactics of state-sponsored cyber actors and highlight the importance of robust cybersecurity measures. Organizations, particularly those in targeted regions and sectors, should remain vigilant against such advanced persistent threats. Implementing comprehensive security protocols, conducting regular system audits, and educating employees about phishing tactics are crucial steps in mitigating the risks posed by groups like Nimbus Manticore.