Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Nimbus Manticore's Sophisticated Cyber Espionage Campaign: A Web of Deception




In a sophisticated cyber espionage campaign, Nimbus Manticore has been linked to the deployment of NightLedger, BridgeHead, ArcBridge, and HollowGraph. These tools allow state-backed hackers to maintain covert access, exfiltrate sensitive data, and disrupt critical infrastructure. The attacks have targeted entities across the Middle East, Africa, and South Asia, highlighting the evolving tactics, techniques, and procedures (TTPs) employed by these groups. Organizations must stay vigilant and adopt proactive measures to prevent such attacks.

  • Nimbus Manticore, a state-backed Iranian hacking group, has been linked to recent attacks in the Middle East, Africa, and South Asia using NightLedger and custom WebSocket tunnelers.
  • The group uses phishing lures masquerading as job opportunities and videoconferencing pages to redirect victims to malicious archives.
  • NightLedger is a previously undocumented Windows backdoor that contacts an external server over HTTPS to parse and run commands.
  • BridgeHead and ArcBridge are custom WebSocket tunnelers used by the group, indicating continued reliance on bespoke tunneling utilities.
  • The use of these tools highlights the evolving tactics, techniques, and procedures (TTPs) employed by state-backed hacking groups.
  • HollowGraph is a new malware sample linked to Cavern Manticore, abusing Microsoft Graph API to create a covert two-way command-and-control channel in compromised Microsoft 365 calendars.



  • Nimbus Manticore, a state-backed Iranian hacking group, has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers, BridgeHead and ArcBridge, with an aim to maintain covert access.

    The exact initial access method used in the attacks is presently unknown, although the adversary is known to employ highly tailored job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as lookalike videoconferencing pages, to redirect recipients to malicious archives hosted on third-party file-sharing services.

    The NightLedger backdoor is designed to contact an external server over HTTPS to parse and run commands in a manner that's analogous to TWOSTROKE, another backdoor deployed by the threat actor in the past. The list of supported commands includes gathering user and host identity information, executing processes, listing directories, downloading files, collecting host and network information, copying or deleting files, updating beacon interval, taking screenshots, loading DLLs, terminating processes, uploading files to a command-and-control server via HTTP POST requests, enumerating logical drives, listing processes, collecting C:\Windows\debug\NetSetup.log diagnostic files together with process-list output.

    The use of BridgeHead and ArcBridge indicates the threat actor's continued use of tunneling utilities, which has been previously observed relying on bespoke tunnelers such as LIGHTRAIL and POLLBLEND. The disclosure comes days after Group-IB uncovered a new malware sample codenamed HollowGraph that's linked to the Cavern (aka Cav3rn) framework used by an Iranian hacking crew dubbed Cavern Manticore.

    HollowGraph abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command-and-control channel. It treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner's attention, every event is dated far into the future - 13 May 2050 - with payloads attached as files to the event.

    The use of NightLedger, BridgeHead, ArcBridge, and HollowGraph highlights the evolving tactics, techniques, and procedures (TTPs) employed by state-backed hacking groups. These tools are designed to maintain covert access, exfiltrate sensitive data, and disrupt critical infrastructure. As cyber espionage continues to be a pressing concern, it is essential for organizations to stay vigilant and adopt proactive measures to prevent such attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Nimbus-Manticores-Sophisticated-Cyber-Espionage-Campaign-A-Web-of-Deception-ehn.shtml

  • https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html

  • https://vulners.com/thn/THN:69380807427ED9F94A9F0A7EFF6A5228

  • https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/

  • https://www.infosecurity-magazine.com/news/iran-nimbus-manticore-european/


  • Published: Tue Jul 28 08:29:05 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us