Iran-Linked Nimbus Manticore Deploys NightLedger Backdoor Across Middle East, Africa, South Asia

New backdoor, familiar actor — the Iran-linked group tracked as Nimbus Manticore has a fresh toolset, and Kaspersky's write-up of NightLedger lands this week.

Share
Flat white line-art of an open back door linked by one line to a distant relay node, on a teal background — the NightLedger backdoor.

Key Takeaways

  • Kaspersky's Securelist on July 28, 2026 documented a fresh toolset from the Iran-linked, state-backed group tracked as Nimbus Manticore (also called GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549), attributing a new set of intrusions across the Middle East, Africa, and South Asia to the actor.
  • The newly documented tooling is a Windows backdoor called NightLedger, reportedly built for reconnaissance, command execution, file operations, process discovery, and screenshot capture, paired with two custom WebSocket tunnelers, ArcBridge and BridgeHead, used to turn compromised systems into covert relays for continued access.
  • Several specifics remain unconfirmed at disclosure — the specific named victim organizations, the initial-access vector, whether the campaign is ongoing at publication, whether the tooling has been seen outside the named region, and any CVE overlap with other Iran-attributed activity; The CyberSignal reports this as a defender-oriented threat-intelligence disclosure, not a reconstruction of tradecraft.

A familiar Iran-linked actor with a fresh backdoor — the defender-relevant facts are the alias set, the NightLedger tooling, and the target region, per Kaspersky's reporting.

MOSCOW — Kaspersky's Securelist on July 28, 2026 documented a previously undocumented toolset attributed to the Iran-linked, state-backed group most widely tracked as Nimbus Manticore, describing a fresh set of intrusions across the Middle East, Africa, and South Asia. The centerpiece is a Windows backdoor the researchers call NightLedger, deployed alongside two custom WebSocket tunnelers named ArcBridge and BridgeHead.

The actor is not new — it carries an unusually long list of vendor aliases, including GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and the Mandiant designation UNC1549. What is new is the tooling and the reported targeting. As reported by The Hacker News, summarizing Kaspersky's write-up, the intrusions reportedly turn compromised systems into covert relays to maintain access. This piece lays out what the disclosure documents and what it does not, without reconstructing how the tooling works.

At a Glance
FieldDetails
ActorIran-linked, state-backed group tracked as Nimbus Manticore
AliasesGalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, UNC1549
Reporting firmKaspersky (Securelist), reported by The Hacker News
New backdoorNightLedger (Windows)
New tunnelersArcBridge and BridgeHead (WebSocket)
Target regionMiddle East, Africa, and South Asia
Disclosure dateJuly 28, 2026
Observed in the wildReported as attributed intrusions; scope and status are open questions

What Kaspersky Documented

According to Kaspersky's Securelist, summarized in reporting by The Hacker News, researchers attributed a fresh set of intrusions to Nimbus Manticore and documented three pieces of previously undocumented tooling: the NightLedger Windows backdoor and two WebSocket tunnelers, ArcBridge and BridgeHead. The reported goal of the tooling is covert, durable access — the tunnelers reportedly turn a compromised machine into a relay node so operator traffic can pass through the victim network.

The reported targeting spans the Middle East, Africa, and South Asia. Kaspersky's account, as relayed in reporting, reportedly points to entities across several countries and sectors in that footprint — including government and small-business environments, aviation, telecommunications, and financial-sector organizations. The CyberSignal is not naming specific victim organizations, which are not established in the material reviewed, and is treating the sector-and-country picture as the reporting firm's characterization rather than a confirmed victim list.

This is a threat-intelligence disclosure from a vendor, not an emergency advisory tied to a single product flaw. There is no CVE at the center of it and, in the reporting reviewed, no exploited vulnerability in a named commercial product is the story. The defender-relevant facts are the actor's identity, the newly documented tooling, and the region — which is what this piece keeps its focus on.

The Nimbus Manticore Alias-Set Problem

One practical hurdle sits in plain sight: this single group answers to at least five names. CrowdStrike's convention is Nimbus Manticore; Kaspersky uses Mirage Kitten; Mandiant and Google track it as UNC1549; other vendors have used GalaxyGato, Smoke Sandstorm, and Subtle Snail. A defender reading three vendor reports could reasonably believe they are looking at three separate actors.

That is not a trivia point. Alias sprawl slows correlation — the moment a security team most needs to connect a new indicator to prior history is the moment the naming gets in the way. For an Iran-linked actor that reappears with new tooling, keeping the alias map straight is part of the defensive work, not a footnote to it. The CyberSignal preserves the full set here for exactly that reason: so a reader who has only seen one of these names can connect this disclosure to the others.

It is also a familiar name for readers of this site. The CyberSignal has previously covered Nimbus Manticore, and the actor sits alongside other Iran-linked activity — from MuddyWater's false-flag tradecraft to the broader threat picture the UK's NCSC has placed Iran within.

The NightLedger, ArcBridge, and BridgeHead Toolset

In defender terms — and without reconstructing tradecraft — the reported toolset splits into two roles. NightLedger is described as the backdoor: a Windows implant reportedly capable of reconnaissance, command execution, file operations, process discovery, and screenshot capture. That is a general-purpose access-and-collection capability, the kind of implant an operator uses to understand a foothold and act on it.

ArcBridge and BridgeHead are described as the movement layer: two custom WebSocket tunnelers whose reported function is to relay operator traffic through a compromised system. The relevant fact for a defender is the design intent, not the mechanics — tunneling over WebSocket lets operator activity blend into ordinary encrypted web traffic, which is what makes the covert-relay framing meaningful. The point for monitoring teams is where to look, not how the tooling is built.

The CyberSignal is deliberately not reproducing configuration details, activation logic, or deployment specifics. Those belong in the primary Kaspersky report for responders who need them; the value here is the shape of the toolset and the fact that a known Iran-linked actor has refreshed it.

What Defenders in the Target Region Should Verify

For organizations inside the reported footprint — the Middle East, Africa, and South Asia, particularly in government, aviation, telecommunications, and financial sectors — the useful posture is verification against the primary source rather than reaction to the headline. The first step is to read Kaspersky's Securelist write-up directly and pull its indicators of compromise, which carry the technical detail this summary intentionally omits.

From there, the defender-relevant questions follow the tooling's reported roles. Because the tunnelers reportedly operate over WebSocket, teams can treat unexpected long-lived WebSocket connections and anomalous outbound relay behavior as worth understanding against their own baselines. Because NightLedger is a Windows backdoor, endpoint telemetry on the reported behaviors — command execution, process discovery, screenshot activity — is where the primary IOCs apply. None of that is a reconstruction of the attack; it is a map of where the published indicators land.

The broader discipline is the one The CyberSignal applies to any nation-state disclosure: take the attribution seriously as reported, verify against the primary source, and resist over-reading a single vendor write-up as a complete picture of the campaign. The reporting frames this as attributed intrusions, and the responsible read is to treat the vendor's account as authoritative on what it documents and silent on what it does not.

Open Questions

Several specifics are unresolved at publication, and The CyberSignal is not filling them in. The specific named victim organizations are not established in the material reviewed. The initial-access vector is not confirmed. Whether the campaign is ongoing at publication, and whether the tooling has been observed outside the named region, are open questions. Any CVE overlap with other Iran-attributed campaigns is likewise not established here.

Those gaps are normal for a first-day vendor disclosure and are the reason this piece attributes the actor's activity as reported rather than asserting it as settled fact. As Kaspersky's full analysis is read, other vendors weigh in, or independent replication of the indicators emerges, the picture will sharpen — and the alias map above is what will let defenders connect the next report to this one.


The CyberSignal Analysis

The reported facts above come from Kaspersky's disclosure and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.

Signal 01 — The Actor Is the Story, Not a New Bug

The instinct with a disclosure is to ask which patch closes it, and this one reportedly frustrates that instinct — there is no CVE at its center. Our reading is that the durable fact here is an actor with a track record refreshing its toolset, not a single defect to remediate. That reframes the work from patch-hunting to actor-tracking: knowing who Nimbus Manticore is, what it targets, and how its tooling tends to behave pays off across the next campaign as much as this one.

The organizations that benefit most are those that already treat named Iran-linked activity as a standing intelligence problem rather than a one-off news item. For them, NightLedger is another data point in a file they already keep; for everyone else, the useful move is to start that file now.

Signal 02 — Alias Sprawl Is a Defensive Liability

The detail we find most practically important is the naming. Five aliases for one group is not a labeling curiosity — it is friction that lands precisely when correlation matters most. Our assessment is that the teams who maintain a clean alias map will connect this disclosure to prior Nimbus Manticore activity in minutes, while those who do not may not realize the connection exists.

That is why we preserve the full set rather than picking one name. The cost of alias sprawl is measured in missed correlations, and the fix is unglamorous: a maintained mapping that survives the next vendor report using a different label for the same actor.

Signal 03 — Verify Against the Primary Source, Then Act

Our posture on a first-day nation-state disclosure is calibrated attention: authoritative on what the vendor documents, cautious about what it does not. Kaspersky's account is the primary source, and the responsible defender move is to pull its indicators directly rather than act on a summary — including this one.

For organizations in the reported region, that means reading the Securelist write-up, extracting the IOCs, and checking them against WebSocket and Windows-endpoint telemetry. For everyone else, it is a reminder that the same Iran-linked actor keeps returning with new tooling — and that the time to understand it is before, not during, the next appearance.


Sources

TypeSource
PrimaryKaspersky Securelist — Mirage Kitten: new tools
ReportingThe Hacker News — Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
RelatedThe CyberSignal — Nimbus Manticore: AI-Assisted Backdoors Target Iranian Aviation Sector
RelatedThe CyberSignal — MuddyWater: Iranian APT, Chaos Ransomware, and False-Flag Microsoft Teams Lures
RelatedThe CyberSignal — The Perfect Storm: NCSC Chief Identifies Iran, Russia, and China as Primary Drivers of UK Cyber Threats