Nimbus Manticore’s Expanding Cyber-Espionage Arsenal Raises a New Warning for the Middle East and Europe + Video

Listen to this Post

Featured ImageA New Chapter in an Evolving Iranian Cyber-Espionage Campaign

Cybersecurity researchers are uncovering a deeper and more sophisticated layer of activity linked to Nimbus Manticore, an Iran-nexus cyber-espionage group associated with the Islamic Revolutionary Guard Corps (IRGC). The latest discoveries reveal previously undocumented malware, covert tunneling capabilities, and infrastructure spread across multiple regions, suggesting that the threat actor continues to refine its ability to penetrate targeted networks and remain hidden for long periods.

The findings are particularly significant because Nimbus Manticore is not simply adding another malware sample to an existing arsenal. Its recent activity shows a broader operational strategy: compromise a target, establish persistent access, disguise malicious components as legitimate Windows software, and use compromised systems as hidden communication or relay points.

Security researchers have increasingly tracked the group under several names, including Mirage Kitten, UNC1549, Smoke Sandstorm, Screening Serpens, GalaxyGato, and Nimbus Manticore. Kaspersky’s recent research independently confirmed that Mirage Kitten, UNC1549, Smoke Sandstorm, and Nimbus Manticore refer to the same threat activity and documented the group’s use of the NightLedger backdoor together with the ArcBridge and BridgeHead tunneling tools.

Why Nimbus Manticore Matters

Nimbus Manticore has a long history of targeting organizations where intelligence can have strategic value, particularly aerospace, aviation, defense, telecommunications, information technology, and government-related environments.

The

This makes the threat particularly difficult to manage. An organization may have strong perimeter security and still be compromised if an employee is persuaded to trust a convincing recruitment message or malicious document.

The Dream Job Strategy Continues to Evolve

One of the most recognizable characteristics associated with Mirage Kitten and related activity is the use of fake job opportunities as an initial lure.

Instead of presenting a victim with an obviously malicious message, attackers can create a believable scenario around employment, recruitment, interviews, technical assessments, or professional networking.

The technique is powerful because it exploits human expectations rather than simply exploiting software vulnerabilities.

Recent Kaspersky reporting also documented recruitment-themed messages impersonating trusted brands and hiring platforms, along with fake videoconferencing pages that redirected selected victims toward malicious archives.

New Malware Shows a More Mature Operational Model

The latest research highlights a collection of tools designed for different stages of an intrusion.

The newly documented ecosystem includes malware capable of maintaining access, collecting information, manipulating files, executing commands, and creating covert communication channels.

Kaspersky’s July 2026 research identified NightLedger, a previously undocumented Windows backdoor, alongside BridgeHead and ArcBridge, two WebSocket-based tunneling tools. These tools were designed to help attackers maintain covert access and use compromised machines as relay points.

This division of capabilities is important.

Rather than depending on one oversized malware program, the attackers can use specialized components for different operational requirements.

NightLedger: A Backdoor Built for Persistence

NightLedger represents the remote-access component of the newly documented toolkit.

According to Kaspersky, the backdoor provides attackers with capabilities including command execution, system reconnaissance, file operations, process discovery, and screenshot capture.

These capabilities transform an infected Windows computer into a remotely manageable asset.

The strategic value is obvious: once attackers have access, they can learn about the environment, determine what systems and files are valuable, and potentially collect sensitive information without immediately revealing their presence.

BridgeHead Turns Victims Into Relay Points

BridgeHead introduces an even more concerning capability.

Instead of merely communicating with an attacker-controlled server, the compromised machine can function as a relay through which additional traffic is routed.

Kaspersky describes BridgeHead as a WebSocket-based tunneling tool capable of effectively turning an infected computer into a network relay. This means attacker-controlled traffic can be routed through the victim’s infrastructure rather than appearing to originate directly from the attacker’s own environment.

That creates an important defensive problem.

Security teams traditionally look for suspicious connections leaving their networks. A compromised host that becomes a relay can make malicious activity appear much closer to legitimate internal traffic.

ArcBridge Adds Another Layer of Covert Connectivity

ArcBridge provides another tunneling capability and was identified earlier in 2026 during activity targeting victims in the Middle East.

Like BridgeHead, it is designed to create covert communication between compromised systems and attacker infrastructure.

The use of multiple tunneling mechanisms suggests that the operators are not relying on a single communication pathway. If one method becomes easier to detect or disrupt, another can potentially be used to preserve access.

The Infrastructure Is Becoming More Distributed

The infrastructure associated with Nimbus Manticore has also become an important part of the investigation.

Researchers have identified infrastructure associated with the

Kaspersky’s victimology included organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, covering government, aviation, telecommunications, financial, and other sectors.

This geographic spread matters because it suggests that the group’s interests are not confined to a single national or regional target set.

The Middle East Remains a Major Focus

The Middle East continues to appear prominently in Nimbus Manticore reporting.

This is consistent with the

For organizations operating in these sectors, the threat should therefore be treated as a strategic intelligence problem rather than simply another malware infection.

The objective of an advanced persistent threat is often not immediate disruption.

The objective can be information.

Europe Is Increasingly Relevant

The reported presence of infrastructure and activity associated with European targets adds another important dimension.

European aerospace, defense, telecommunications, technology, and government organizations can possess information of considerable geopolitical value.

If the group is expanding its operational footprint, organizations outside its historically emphasized target regions should not assume they are irrelevant simply because they are not located in the Middle East.

The TWOSTROKE Connection

Another important discovery described in the original research is a newly identified backdoor showing similarities to TWOSTROKE, a previously attributed C++ implant.

The malware family is designed around conventional but powerful remote-access functions, including information collection, file manipulation, dynamic loading, and persistence.

The similarity between newly discovered tooling and previously attributed malware is valuable to threat researchers because malware development patterns can help connect seemingly unrelated campaigns.

Code reuse, architectural similarities, communication patterns, and operational habits can all contribute to attribution.

Why Malware Masquerading Is So Effective

One of the more interesting characteristics of the newly reported malware is its effort to resemble legitimate Windows components.

A malicious file that appears to have a familiar name can potentially reduce suspicion among users and automated security systems.

This is not a new technique, but its continued use demonstrates why defenders cannot rely solely on filenames or apparent software identity.

A file resembling a legitimate Windows component is not necessarily legitimate.

Its location, parent process, digital signature, network behavior, loading sequence, and relationship with other processes are equally important.

The Real Threat Is Persistence

The most important lesson from this campaign is not the name of any individual malware sample.

It is persistence.

Nimbus

A backdoor provides access.

A tunneling tool provides concealment and network reach.

Together, these capabilities can create a much more resilient intrusion.

Social Engineering Remains a Critical Weakness

Advanced attackers continue to demonstrate that sophisticated malware does not always require sophisticated initial deception.

A convincing email can still be enough.

A fake recruitment conversation can still be enough.

A fraudulent interview platform can still be enough.

The security chain often begins with a human decision, which means technical defenses must be combined with awareness training, identity protection, endpoint monitoring, and strong authentication.

The Shift From Malware to Infrastructure

Another important development is the growing importance of infrastructure itself.

Modern state-linked intrusion campaigns are increasingly designed around ecosystems rather than isolated malware samples.

Attackers need command-and-control infrastructure, fallback systems, tunneling mechanisms, staging locations, authentication techniques, and methods for hiding traffic.

When defenders disrupt only one malware sample, the larger campaign can survive.

The infrastructure must therefore become part of the defensive picture.

Deep Analysis

A Campaign Built Around Long-Term Access

The available evidence points toward an operation designed for persistence rather than rapid disruption. NightLedger, BridgeHead, and ArcBridge provide complementary capabilities that can help an attacker retain access while limiting obvious network exposure.

Multiple Tools Mean Greater Operational Flexibility

A modular toolkit gives operators flexibility. One component can provide remote control while another handles tunneling and another performs specialized collection or execution.

Tunneling Changes the Detection Equation

A compromised endpoint that becomes a relay can make malicious traffic harder to distinguish from ordinary traffic leaving the organization.

The Victim Can Become Part of the Attack Infrastructure

This is one of the most significant implications of the campaign. The compromised computer is no longer merely a target; it can become an operational resource for the attackers.

Attribution Benefits From Reused Tradecraft

Similarities between new malware and previously documented tools can help researchers connect campaigns and establish stronger attribution assessments.

Social Engineering Remains Central

Despite the technical sophistication of the malware, recruitment-themed social engineering remains an important part of the broader tradecraft.

Fake Employment Opportunities Exploit Trust

Job-related communication naturally encourages users to open documents, visit websites, download files, and communicate with unfamiliar individuals.

Aerospace Organizations Remain High-Value Targets

Aerospace and aviation organizations can hold sensitive information involving engineering, logistics, procurement, operations, and national security.

Telecommunications Providers Are Strategic Targets

Telecommunications environments provide visibility into communications infrastructure and can offer valuable intelligence to state-sponsored actors.

Government Networks Offer Intelligence Value

Government environments can contain diplomatic, administrative, strategic, and operational information that is valuable for espionage.

Financial Organizations Are Also Exposed

Financial institutions can reveal economic activity, transaction patterns, and broader information about organizations or individuals of interest.

Regional Expansion Increases the Defensive Burden

The wider the geographic footprint, the more organizations need to consider the threat during their threat-modeling exercises.

Cloud Infrastructure Can Complicate Attribution

When malicious infrastructure uses common cloud services or hosted environments, defenders may have difficulty distinguishing malicious activity from legitimate traffic.

HTTPS Is Not Automatically Safe

Encrypted communications protect data in transit, but encryption does not make the destination trustworthy.

WebSocket Traffic Deserves More Attention

WebSocket communications can be legitimate, but unexpected persistent WebSocket connections from unusual applications or servers should receive additional scrutiny.

Endpoint Context Matters

Security teams should evaluate which processes initiate network connections, where binaries are located, and whether their behavior matches their apparent purpose.

Filename-Based Detection Is Not Enough

Attackers can imitate legitimate names, so behavioral analysis is more reliable than simply searching for suspicious filenames.

Persistence Must Be Investigated

A successful intrusion is not necessarily finished when the initial malware is removed. Defenders should investigate how access was established and whether additional persistence mechanisms remain.

Incident Response Must Look Beyond One Host

When tunneling tools are involved, analyzing a single infected machine may not reveal the complete scope of the intrusion.

Network Segmentation Can Reduce Damage

Strong segmentation can limit what a compromised workstation can reach, reducing the value of that machine as a relay or pivot point.

Identity Security Is Increasingly Important

Strong authentication, phishing-resistant credentials, and carefully controlled privileged access can make social-engineering campaigns substantially harder to convert into persistent access.

Security Teams Should Watch for Anomalous Outbound Traffic

Unexpected encrypted communications, unusual destinations, and persistent connections from applications that normally have no reason to communicate externally deserve investigation.

Employee Training Still Matters

Technical controls cannot fully compensate for users who are repeatedly exposed to convincing recruitment-themed attacks.

Threat Intelligence Can Improve Detection

Organizations in sectors historically targeted by Nimbus Manticore should incorporate relevant threat intelligence into detection rules and hunting activities.

Hunt for Behavior, Not Just Indicators

Static indicators can become obsolete. Behavioral patterns such as unusual DLL loading, unexpected network tunneling, and suspicious persistence can remain useful even when infrastructure changes.

Attackers Can Replace Infrastructure Quickly

Blocking a single address or domain may disrupt an operation temporarily, but it does not necessarily eliminate the underlying threat actor.

Modular Malware Can Accelerate Recovery Challenges

If different components serve different functions, removing one component may not remove every capability.

Attribution Does Not Equal Complete Visibility

Researchers can confidently connect malware families to a threat actor while still lacking visibility into every victim, infrastructure node, or operational objective.

The Campaign Shows Continued Investment

The development of new malware and tunneling tools indicates that the group continues investing resources in its operational capabilities.

Detection Must Become Layered

Endpoint, identity, network, email, DNS, and cloud telemetry should be correlated rather than investigated independently.

Organizations Should Assume Persistence Is Possible

When an advanced threat actor gains access, defenders should investigate whether the attacker established secondary mechanisms for returning later.

The Biggest Risk Is False Confidence

An organization that blocks one known malware family but does not examine the surrounding intrusion may believe it is safe while the attacker remains present.

The Broader Lesson for 2026

Nimbus Manticore demonstrates how modern state-sponsored cyber-espionage is becoming more adaptable, modular, and infrastructure-focused.

What Undercode Say: The Threat Is Bigger Than the Malware

The discovery of additional Nimbus Manticore infrastructure should not be interpreted simply as another malware announcement.

The more important development is the combination of social engineering, persistence, custom malware, covert tunneling, and infrastructure flexibility.

The group appears to understand that remaining invisible can be more valuable than causing immediate damage.

That changes the defensive equation.

Traditional antivirus detection remains important, but it cannot be the entire strategy.

An attacker who uses legitimate-looking filenames, encrypted communications, cloud-hosted infrastructure, and compromised machines as relays can potentially avoid many simplistic detection methods.

The use of multiple tools is particularly significant.

NightLedger can provide remote access and reconnaissance, while ArcBridge and BridgeHead can provide covert connectivity.

This resembles an operational toolkit rather than a single-purpose malware campaign.

The targeting profile is equally important.

Aerospace, aviation, telecommunications, defense, government, and financial organizations are all environments where sensitive information can have strategic value.

The geographic distribution reported by Kaspersky demonstrates that this is not a narrowly localized operation.

Organizations in the Middle East and Africa should take the findings seriously, but European organizations should also pay attention to the broader infrastructure and targeting patterns.

The continued use of recruitment-themed lures is another reminder that attackers do not need to invent a new psychological trick every year.

People still trust professional opportunities.

They still open interview documents.

They still follow links sent by people who appear credible.

That makes identity verification and employee awareness just as important as endpoint protection.

The tunneling capability deserves particular attention because it changes how defenders should think about compromised hosts.

A compromised computer can become part of the attacker’s infrastructure.

That means unusual outbound traffic from an otherwise ordinary workstation can be more important than the malware filename itself.

Security teams should therefore investigate the relationship between processes, files, authentication events, DNS requests, outbound connections, and persistence mechanisms.

Another important lesson is that attribution evolves over time.

As researchers discover new samples and infrastructure, previously separate campaigns can become connected.

This helps defenders understand the broader threat actor instead of treating every incident as an isolated event.

The reported similarities with TWOSTROKE are particularly useful in this context because malware development patterns can reveal continuity even when infrastructure changes.

The apparent evolution of the toolkit also suggests that defenders should expect future variants.

Blocking today’s indicators is necessary, but preparing for tomorrow’s indicators is even more important.

Behavioral detection provides a stronger long-term strategy.

Organizations should look for abnormal persistence, suspicious DLL behavior, unexpected encrypted connections, unusual WebSocket activity, and network traffic generated by applications that normally have little reason to communicate externally.

Incident response teams should also assume that an advanced intrusion may involve more than one compromised endpoint.

If a machine has been converted into a relay, other systems may have interacted with it.

That makes network-wide investigation essential.

The campaign also reinforces the value of segmentation.

If a compromised workstation cannot freely communicate with sensitive servers, the attacker’s options become more limited.

Likewise, privileged accounts should not be casually accessible from ordinary endpoints.

Strong identity controls can dramatically reduce the impact of phishing and social engineering.

The broader message is clear: cybersecurity defenses must be designed around attacker behavior rather than malware names.

Nimbus

Its infrastructure may change.

Its filenames may change.

Its lures may change.

But the underlying objectives—initial access, persistence, reconnaissance, covert communication, and intelligence collection—are much more stable.

That is where defenders should focus.

✅ The discovery of NightLedger, BridgeHead, and ArcBridge is supported by Kaspersky’s July 28, 2026 research, which identifies Mirage Kitten, UNC1549, Smoke Sandstorm, and Nimbus Manticore as associated names and documents the three-tool malware set.

✅ The targeting of organizations across the Middle East and Africa is supported, with Kaspersky identifying victims or activity involving Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso.

❌ Some attribution and organizational relationships in the original article should be treated as assessments rather than absolute facts, because threat-intelligence naming conventions and relationships between Iranian APT clusters can vary among security vendors.

Prediction

(-1) Nimbus Manticore is likely to continue developing new malware and communication mechanisms as defenders become familiar with NightLedger, BridgeHead, ArcBridge, and related infrastructure.

(-1) Targeted recruitment and social-engineering campaigns are likely to remain effective, particularly against aerospace, defense, telecommunications, government, and technology organizations.

(-1) The use of compromised systems as network relays is likely to become an increasingly important concern, because it allows attackers to hide parts of their activity behind trusted victim infrastructure.

(+1) Behavior-based detection and stronger identity security can significantly reduce the group’s chances of maintaining long-term access, especially when organizations combine endpoint telemetry, network monitoring, segmentation, phishing-resistant authentication, and threat hunting.

(+1) The continued publication of detailed threat-intelligence research gives defenders an opportunity to detect future activity earlier, particularly when organizations translate published behavioral findings into practical monitoring and incident-response procedures.

Final Assessment: A Warning About the Next Stage of State-Sponsored Espionage

Nimbus Manticore’s latest activity demonstrates how state-sponsored cyber-espionage continues to evolve beyond conventional malware deployment.

The most concerning element is not one specific backdoor or one infrastructure address.

It is the combination of carefully engineered social engineering, custom Windows malware, persistent access, covert tunneling, and the ability to turn compromised machines into operational relay points.

The group appears to be adapting its methods to make detection more difficult while expanding the environments in which it can operate.

For defenders, the response should be equally adaptive.

The strongest protection will come from combining human awareness with identity security, endpoint monitoring, network segmentation, behavioral detection, threat intelligence, and disciplined incident response.

The lesson from Nimbus Manticore is ultimately simple: an attacker does not need to make a compromised machine look malicious if they can make it look useful, legitimate, and invisible.

▶️ Related Video (78% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.instagram.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube