Executive Summary
In July 2026, the Iranian state-sponsored hacking group known as Nimbus Manticore (also referred to as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) launched a series of cyber attacks targeting entities across the Middle East, Africa, and South Asia. The group employed a previously undocumented Windows backdoor named NightLedger, along with two custom WebSocket-based tunnelers, BridgeHead and ArcBridge, to maintain covert access to compromised systems. These tools enabled the attackers to perform reconnaissance, execute commands, and establish covert network access, effectively turning victim systems into relay nodes for further malicious activities.
This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly developing and deploying sophisticated malware to achieve persistent access and control over targeted networks. The use of custom tunneling tools and backdoors highlights the need for organizations to enhance their detection and response capabilities to counter such advanced threats.
Why This Matters Now
The deployment of NightLedger and associated tunneling tools by Nimbus Manticore demonstrates a significant advancement in cyber-espionage tactics, emphasizing the urgency for organizations to bolster their cybersecurity defenses against increasingly sophisticated state-sponsored attacks.
Attack Path Analysis
Nimbus Manticore initiated the attack by impersonating recruiters to deliver malicious payloads via fake job portals. They escalated privileges by exploiting legitimate software processes through AppDomain hijacking. The attackers moved laterally within the network using custom implants and abused trusted cloud infrastructure. They established command and control channels by deploying backdoors like MiniFast, enabling remote control over compromised systems. Data exfiltration was conducted through encrypted channels to evade detection. The impact included unauthorized access to sensitive information and potential disruption of critical services.
Kill Chain Progression
Initial Compromise
Description
The attackers used spear-phishing campaigns, impersonating recruiters to lure victims into downloading malicious payloads from fake job portals.
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Exploitation for Client Execution
Boot or Logon Autostart Execution: Registry Run Keys
Application Layer Protocol: Web Protocols
Command and Scripting Interpreter: PowerShell
Account Discovery: Domain Account
Account Manipulation: Additional Email Delegate Permissions
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that security policies and operational procedures for detecting and responding to failures are documented, in use, and known to all affected parties.
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Management and Access Control
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Iranian APT Nimbus Manticore targeting Middle East entities creates critical risks for government systems through NightLedger backdoor and WebSocket tunnelers enabling persistent access.
Oil/Energy/Solar/Greentech
State-sponsored attacks with covert relay capabilities pose severe threats to energy infrastructure through encrypted traffic manipulation and east-west lateral movement across operational networks.
Telecommunications
APT group's WebSocket tunneling and traffic relay methods directly threaten telecom infrastructure integrity, enabling command-and-control channels through compromised network equipment and services.
Financial Services
Advanced persistent threat deploying NightLedger backdoor creates significant risks for financial institutions through zero trust segmentation bypasses and encrypted data exfiltration capabilities.
Sources
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relayshttps://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.htmlVerified
- Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling toolshttps://securelist.com/mirage-kitten-new-tools/120811/Verified
- Mirage Kitten targets Middle East and Africa region with new malwarehttps://gixtools.net/2026/07/mirage-kitten-targets-middle-east-and-africa-region-with-new-malware/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and egress controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on network-level controls, it could have limited the attacker's ability to exploit compromised credentials by enforcing strict network segmentation and access controls.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing strict access controls between workloads.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could have restricted the attacker's lateral movement by enforcing segmentation and monitoring internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could have limited the establishment of command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could have restricted data exfiltration by controlling and monitoring outbound traffic.
Aviatrix Zero Trust CNSF could have reduced the impact by limiting the attacker's access to sensitive information and critical services through strict segmentation and access controls.
Impact at a Glance
Affected Business Functions
- Government Services
- Aviation Operations
- Telecommunications
- Financial Services
Estimated downtime: 7 days
Estimated loss: $500,000
Sensitive government documents, aviation operational data, telecommunications customer information, financial transaction records
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic flows.
- • Utilize Multicloud Visibility & Control solutions to detect and respond to anomalous activities across cloud environments.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration.
- • Adopt Threat Detection & Anomaly Response mechanisms to identify and mitigate malicious activities promptly.



