Iran-Linked Nimbus Manticore Deploys NightLedger Backdoor Across Middle East, Africa, South Asia
New backdoor, familiar actor — the Iran-linked group tracked as Nimbus Manticore has a fresh toolset, and Kaspersky's write-up of NightLedger lands this week.
Key Takeaways
|
A familiar Iran-linked actor with a fresh backdoor — the defender-relevant facts are the alias set, the NightLedger tooling, and the target region, per Kaspersky's reporting.
MOSCOW — Kaspersky's Securelist on July 28, 2026 documented a previously undocumented toolset attributed to the Iran-linked, state-backed group most widely tracked as Nimbus Manticore, describing a fresh set of intrusions across the Middle East, Africa, and South Asia. The centerpiece is a Windows backdoor the researchers call NightLedger, deployed alongside two custom WebSocket tunnelers named ArcBridge and BridgeHead.
The actor is not new — it carries an unusually long list of vendor aliases, including GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and the Mandiant designation UNC1549. What is new is the tooling and the reported targeting. As reported by The Hacker News, summarizing Kaspersky's write-up, the intrusions reportedly turn compromised systems into covert relays to maintain access. This piece lays out what the disclosure documents and what it does not, without reconstructing how the tooling works.
| At a Glance | |
|---|---|
| Field | Details |
| Actor | Iran-linked, state-backed group tracked as Nimbus Manticore |
| Aliases | GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, UNC1549 |
| Reporting firm | Kaspersky (Securelist), reported by The Hacker News |
| New backdoor | NightLedger (Windows) |
| New tunnelers | ArcBridge and BridgeHead (WebSocket) |
| Target region | Middle East, Africa, and South Asia |
| Disclosure date | July 28, 2026 |
| Observed in the wild | Reported as attributed intrusions; scope and status are open questions |
What Kaspersky Documented
According to Kaspersky's Securelist, summarized in reporting by The Hacker News, researchers attributed a fresh set of intrusions to Nimbus Manticore and documented three pieces of previously undocumented tooling: the NightLedger Windows backdoor and two WebSocket tunnelers, ArcBridge and BridgeHead. The reported goal of the tooling is covert, durable access — the tunnelers reportedly turn a compromised machine into a relay node so operator traffic can pass through the victim network.
The reported targeting spans the Middle East, Africa, and South Asia. Kaspersky's account, as relayed in reporting, reportedly points to entities across several countries and sectors in that footprint — including government and small-business environments, aviation, telecommunications, and financial-sector organizations. The CyberSignal is not naming specific victim organizations, which are not established in the material reviewed, and is treating the sector-and-country picture as the reporting firm's characterization rather than a confirmed victim list.
This is a threat-intelligence disclosure from a vendor, not an emergency advisory tied to a single product flaw. There is no CVE at the center of it and, in the reporting reviewed, no exploited vulnerability in a named commercial product is the story. The defender-relevant facts are the actor's identity, the newly documented tooling, and the region — which is what this piece keeps its focus on.
The Nimbus Manticore Alias-Set Problem
One practical hurdle sits in plain sight: this single group answers to at least five names. CrowdStrike's convention is Nimbus Manticore; Kaspersky uses Mirage Kitten; Mandiant and Google track it as UNC1549; other vendors have used GalaxyGato, Smoke Sandstorm, and Subtle Snail. A defender reading three vendor reports could reasonably believe they are looking at three separate actors.
That is not a trivia point. Alias sprawl slows correlation — the moment a security team most needs to connect a new indicator to prior history is the moment the naming gets in the way. For an Iran-linked actor that reappears with new tooling, keeping the alias map straight is part of the defensive work, not a footnote to it. The CyberSignal preserves the full set here for exactly that reason: so a reader who has only seen one of these names can connect this disclosure to the others.
It is also a familiar name for readers of this site. The CyberSignal has previously covered Nimbus Manticore, and the actor sits alongside other Iran-linked activity — from MuddyWater's false-flag tradecraft to the broader threat picture the UK's NCSC has placed Iran within.
The NightLedger, ArcBridge, and BridgeHead Toolset
In defender terms — and without reconstructing tradecraft — the reported toolset splits into two roles. NightLedger is described as the backdoor: a Windows implant reportedly capable of reconnaissance, command execution, file operations, process discovery, and screenshot capture. That is a general-purpose access-and-collection capability, the kind of implant an operator uses to understand a foothold and act on it.
ArcBridge and BridgeHead are described as the movement layer: two custom WebSocket tunnelers whose reported function is to relay operator traffic through a compromised system. The relevant fact for a defender is the design intent, not the mechanics — tunneling over WebSocket lets operator activity blend into ordinary encrypted web traffic, which is what makes the covert-relay framing meaningful. The point for monitoring teams is where to look, not how the tooling is built.
The CyberSignal is deliberately not reproducing configuration details, activation logic, or deployment specifics. Those belong in the primary Kaspersky report for responders who need them; the value here is the shape of the toolset and the fact that a known Iran-linked actor has refreshed it.
What Defenders in the Target Region Should Verify
For organizations inside the reported footprint — the Middle East, Africa, and South Asia, particularly in government, aviation, telecommunications, and financial sectors — the useful posture is verification against the primary source rather than reaction to the headline. The first step is to read Kaspersky's Securelist write-up directly and pull its indicators of compromise, which carry the technical detail this summary intentionally omits.
From there, the defender-relevant questions follow the tooling's reported roles. Because the tunnelers reportedly operate over WebSocket, teams can treat unexpected long-lived WebSocket connections and anomalous outbound relay behavior as worth understanding against their own baselines. Because NightLedger is a Windows backdoor, endpoint telemetry on the reported behaviors — command execution, process discovery, screenshot activity — is where the primary IOCs apply. None of that is a reconstruction of the attack; it is a map of where the published indicators land.
The broader discipline is the one The CyberSignal applies to any nation-state disclosure: take the attribution seriously as reported, verify against the primary source, and resist over-reading a single vendor write-up as a complete picture of the campaign. The reporting frames this as attributed intrusions, and the responsible read is to treat the vendor's account as authoritative on what it documents and silent on what it does not.
Open Questions
Several specifics are unresolved at publication, and The CyberSignal is not filling them in. The specific named victim organizations are not established in the material reviewed. The initial-access vector is not confirmed. Whether the campaign is ongoing at publication, and whether the tooling has been observed outside the named region, are open questions. Any CVE overlap with other Iran-attributed campaigns is likewise not established here.
Those gaps are normal for a first-day vendor disclosure and are the reason this piece attributes the actor's activity as reported rather than asserting it as settled fact. As Kaspersky's full analysis is read, other vendors weigh in, or independent replication of the indicators emerges, the picture will sharpen — and the alias map above is what will let defenders connect the next report to this one.
The CyberSignal Analysis
The reported facts above come from Kaspersky's disclosure and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.
Signal 01 — The Actor Is the Story, Not a New Bug
The instinct with a disclosure is to ask which patch closes it, and this one reportedly frustrates that instinct — there is no CVE at its center. Our reading is that the durable fact here is an actor with a track record refreshing its toolset, not a single defect to remediate. That reframes the work from patch-hunting to actor-tracking: knowing who Nimbus Manticore is, what it targets, and how its tooling tends to behave pays off across the next campaign as much as this one.
The organizations that benefit most are those that already treat named Iran-linked activity as a standing intelligence problem rather than a one-off news item. For them, NightLedger is another data point in a file they already keep; for everyone else, the useful move is to start that file now.
Signal 02 — Alias Sprawl Is a Defensive Liability
The detail we find most practically important is the naming. Five aliases for one group is not a labeling curiosity — it is friction that lands precisely when correlation matters most. Our assessment is that the teams who maintain a clean alias map will connect this disclosure to prior Nimbus Manticore activity in minutes, while those who do not may not realize the connection exists.
That is why we preserve the full set rather than picking one name. The cost of alias sprawl is measured in missed correlations, and the fix is unglamorous: a maintained mapping that survives the next vendor report using a different label for the same actor.
Signal 03 — Verify Against the Primary Source, Then Act
Our posture on a first-day nation-state disclosure is calibrated attention: authoritative on what the vendor documents, cautious about what it does not. Kaspersky's account is the primary source, and the responsible defender move is to pull its indicators directly rather than act on a summary — including this one.
For organizations in the reported region, that means reading the Securelist write-up, extracting the IOCs, and checking them against WebSocket and Windows-endpoint telemetry. For everyone else, it is a reminder that the same Iran-linked actor keeps returning with new tooling — and that the time to understand it is before, not during, the next appearance.