Iran-linked hackers turn victim machines into covert relays with NightLedger

Nimbus Manticore deploys NightLedger backdoor and custom WebSocket tunnelers to turn compromised systems into covert relay nodes across the Middle East and Africa.

CSBadmin
2 Min Read

Iranian state-sponsored threat actors have deployed a previously undocumented Windows backdoor dubbed NightLedger across a sprawling campaign targeting government agencies, aviation firms, telecom providers, and financial institutions in the Middle East, Africa, and South Asia, according to research released by Kaspersky’s Global Research and Analysis Team

The activity is attributed to Mirage Kitten, a persistent espionage group also tracked under the aliases Nimbus Manticore, Smoke Sandstorm, and UNC1549

Kaspersky’s telemetry shows confirmed victims across Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso — consistent with the group’s established focus on strategic intelligence gathering in those regions

NightLedger arrives on target machines through a technique that exploits Windows DLL search-order behavior

A legitimate binary, AppVShNotify.exe, indirectly loads a malicious SspiCli.dll placed in the same directory, because AppVShNotify.exe imports RPCRT4.dll, which can delay-load SspiCli.dll during authentication routines

Once executed, the backdoor beacons to a command server over HTTPS and interprets responses split by a custom delimiter — an approach that mirrors the command-parsing design of an earlier Mirage Kitten tool called TWOSTROKE

Its capabilities span reconnaissance, process and file management, screenshot capture, directory listing, DLL injection, and data exfiltration via HTTP POST requests

Alongside the backdoor, Kaspersky identified two WebSocket tunneling tools that turn infected systems into covert relay nodes

BridgeHead operates as a SOCKS5 proxy, routing operator-initiated TCP connections through compromised machines so malicious traffic appears to originate from the victim’s own network

It was observed in Egypt and at an aerospace organization in Pakistan

A second tool, ArcBridge, first spotted in April 2026, provides comparable relay functionality and was deployed against targets in the Middle East

While the specific initial infection vector remains unconfirmed, Mirage Kitten has historically gained entry through targeted phishing campaigns — typically job-offer lures impersonating well-known companies and links to fraudulent videoconferencing platforms

The disclosure follows.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.