An Iranian state-sponsored hacking group known as Nimbus Manticore has been linked to a recent series of cyberattacks on organizations in the Middle East, Africa, and South Asia. Utilizing a newly discovered Windows backdoor called NightLedger, the group aims to maintain clandestine access to affected systems.
Targeted Regions and Sectors
The attacks have impacted a variety of sectors, including governments and small-to-medium businesses in Jordan and Tanzania, aviation firms in Pakistan, telecommunications in Ethiopia, and financial institutions in Burkina Faso. This information comes from cybersecurity firm Kaspersky, which has been tracking the group’s activities.
In addition to NightLedger, the attackers employ two custom WebSocket tunnelers, BridgeHead and ArcBridge, to ensure persistent and covert network access. These tools are part of a broader espionage toolkit designed to extract sensitive information from compromised systems.
Technical Details of NightLedger
NightLedger is a sophisticated Windows backdoor capable of executing commands, gathering system information, and capturing screenshots. It operates by connecting to an external server over HTTPS to execute commands, similar to the previously observed TWOSTROKE backdoor.
The malware’s functionality includes process execution, file manipulation, and data exfiltration. It also allows the threat actor to remotely update its operational parameters and maintain its presence on the victim’s network.
Methods of Initial Compromise
Although the initial access method remains unclear, Nimbus Manticore is known to use targeted phishing campaigns. These campaigns often mimic well-known brands and job platforms, redirecting victims to malicious websites disguised as legitimate services.
The attackers then leverage these deceptive tactics to deliver their payloads, including the NightLedger backdoor, through DLL side-loading techniques. This approach allows them to bypass security measures and establish a foothold in the targeted network.
Advanced Tunneling Techniques
BridgeHead and ArcBridge, the group’s custom tunneling tools, facilitate covert communication between the compromised systems and the attackers’ command-and-control servers. By relaying traffic through the victim’s network, these tools obfuscate the source of the malicious activity.
This strategy underscores the threat actor’s continued reliance on tunneling utilities, as seen in their previous operations involving bespoke tools like LIGHTRAIL and POLLBLEND.
Conclusion and Outlook
The revelations about Nimbus Manticore’s recent campaign highlight the persistent threat posed by state-sponsored actors. Their use of advanced malware and tunneling techniques demonstrates a high level of sophistication aimed at evading detection and maintaining long-term access to sensitive networks.
As cybersecurity experts continue to unravel these complex attacks, organizations must remain vigilant and enhance their defensive measures to protect against such sophisticated threats.
