"The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling," Kaspersky researchers Omar Amin and Vasily Berdnikov said.
Nimbus Manticore's new toolkit
The actor tracked as Nimbus Manticore — also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549 — has been linked to a fresh wave of intrusions across the Middle East, Africa, and South Asia, according to Kaspersky. The new campaign centers on a previously undocumented Windows backdoor named NightLedger and two bespoke WebSocket-based tunnelers, BridgeHead and ArcBridge, employed to maintain covert access and to proxy operator traffic through compromised hosts.
NightLedger: features, delivery, and command set
Kaspersky reports NightLedger is launched as a DLL via DLL side-loading and is designed to contact an external server over HTTPS to parse and execute operator instructions in a manner "analogous to TWOSTROKE," a backdoor previously used by the actor. The researchers list NightLedger's capabilities as including reconnaissance, command execution, file operations, process discovery and control, and screenshot capture. Explicitly supported commands include:
- Gather user and host identity information
- Execute a process/program
- List directories
- Download a file to the infected system
- Collect host and network information
- Copy or delete files
- Update beacon interval
- Take a screenshot
- Load a DLL
- Terminate a process or thread
- Upload file to the command-and-control (C2) server via an HTTP POST request
- Enumerate logical drives
- List processes
- Collect C:\Windows\debug\NetSetup.log together with process-list output
BridgeHead and ArcBridge: turning victims into relays
Kaspersky describes BridgeHead (observed as "unbcl.dll") as a SOCKS5 tunnel proxy seen in Egypt and Pakistan that shares functional overlap with malware families such as MiniFast (aka MiniUpdate and Retrograde). ArcBridge, another WebSocket tunneling tool, was observed in April 2026 against targets in the Middle East.
About BridgeHead, Kaspersky wrote: "The C2 server initiates all tunnel connections by sending binary commands over the WebSocket; the implant simply forwards traffic between server-specified targets and the WebSocket channel." That design makes infected machines relay nodes: the operator runs tools server-side and tunnels all resulting TCP traffic through the victim host as if originating from the victim's network. The researchers note this continues Nimbus Manticore's long-standing use of bespoke tunneling utilities, following prior tools such as LIGHTRAIL and POLLBLEND.
Geographic and sector footprint
Kaspersky attributes activity to a range of sectors and countries. Reported targets include Egypt; small and medium businesses and government environments in Jordan and Tanzania; aviation organizations in Pakistan; telecommunication companies in Ethiopia; and financial-sector entities in Burkina Faso. Kaspersky did not specify the initial access vector for these incidents but noted the actor's known preference for highly tailored lures.
The adversary commonly uses job opportunity–themed phishing masquerading as trusted brands and hiring platforms, along with lookalike videoconferencing pages that redirect recipients to malicious archives hosted on third-party file-sharing services. Those archives are then used to deliver payloads including NightLedger and the tunneling implants.
Related activity: HOLLOWGRAPH and the Cavern framework
Days after Kaspersky's disclosure, Group-IB published findings on a different sample codenamed HOLLOWGRAPH, which it associated with a Cavern (aka Cav3rn) framework used by a separate Iranian-linked crew called Cavern Manticore. Group-IB said HOLLOWGRAPH "abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel."
Group-IB described how the technique treats a compromised mailbox's calendar "as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached." To avoid alerting mailbox owners, each event is dated far into the future — "13 May 2050" — with payloads attached as files to the event, Group-IB reported.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Expect adversaries to combine stealthy backdoors with network-level tunnelers that convert compromised hosts into operator-controlled relays; detection strategies should include monitoring unusual WebSocket activity and DLL side-loading behavior.
- Policymakers and regulators: The cross-border targeting of aviation, telecommunications, financial, government, and SMB environments highlights an operational pattern that may warrant coordinated disclosure and cross-jurisdictional incident response mechanisms.
- Affected enterprises and procurement leaders: Tailored job-lure phishing and lookalike conferencing pages remain active vectors; supply-chain and employee-facing controls for archive handling and link verification are an immediate control consideration.
The disclosures from Kaspersky and Group-IB together sketch a continuing evolution in tradecraft: native backdoors paired with WebSocket-based relay tooling, and creative abuse of legitimate cloud APIs for covert C2. For defenders, the pressing questions are practical — which telemetry will reveal a relay in use, and how to disrupt operator-side infrastructure once a victim host is identified. Kaspersky's and Group-IB's reports leave those operational puzzles to incident responders on the ground.




