Actor Profile

Nimbus Manticore (also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) is an Iranian state-backed advanced persistent threat group conducting cyber espionage operations. The group is motivated by intelligence collection objectives aligned with Iranian state interests, targeting government, telecommunications, aviation, and financial sectors across the Middle East, Africa, and South Asia. Nimbus Manticore is known for sophisticated social engineering using job opportunity-themed phishing lures masquerading as trusted brands and hiring platforms, as well as deploying custom malware and tunneling infrastructure to maintain persistent covert access to victim networks.

TTPs (Tactics, Techniques, Procedures)

The group employs highly tailored phishing campaigns using job opportunity lures and lookalike videoconferencing pages to redirect targets to malicious archives on third-party file-sharing services (T1566.001, T1566.002). Initial access method remains undetermined in recent campaigns. Post-compromise, the actor uses DLL side-loading (T1574.002) to execute the NightLedger backdoor, which performs reconnaissance (T1082, T1033), command execution (T1059), file operations (T1005, T1083), process discovery (T1057), and screenshot capture (T1113). The group deploys custom WebSocket-based tunnelers (BridgeHead and ArcBridge) to establish SOCKS5 proxies and turn victim systems into covert relay nodes for C2 traffic (T1090.001, T1572). NightLedger communicates over HTTPS (T1071.001) with external C2 servers. The toolset enables data exfiltration via HTTP POST (T1041) and maintains persistence through custom tunneling utilities similar to previously observed LIGHTRAIL and POLLBLEND tunnelers.

Targets & Patterns

Nimbus Manticore targets entities across the Middle East, Africa, and South Asia, with specific focus on strategic sectors aligned with Iranian intelligence priorities. Observed targets include SMB and government environments in Egypt, Jordan, and Tanzania; aviation organizations in Pakistan; telecommunication companies in Ethiopia; and financial-sector entities in Burkina Faso. The targeting pattern reflects interest in critical infrastructure, government intelligence, and sectors with regional strategic value. The use of job opportunity-themed phishing suggests the group profiles individuals with access to sensitive networks, likely focusing on employees in positions with elevated privileges or access to classified information. The geographic spread indicates a broad regional intelligence collection mandate spanning multiple continents.

Historical Context

Nimbus Manticore has demonstrated consistent operational patterns in deploying custom backdoors and tunneling infrastructure. The NightLedger backdoor shares functional similarities with TWOSTROKE, a previously attributed backdoor used by the group. The deployment of BridgeHead and ArcBridge continues the actor's established tradecraft of using bespoke tunneling utilities, including previously documented tools such as LIGHTRAIL, POLLBLEND, and MiniFast (aka MiniUpdate and Retrograde). BridgeHead shows functional overlaps with MiniFast, indicating iterative development of the group's tunneling capabilities. The recent disclosure follows closely after Group-IB's identification of HOLLOWGRAPH malware linked to Cavern Manticore, another Iranian threat actor using the Cavern (Cav3rn) framework, suggesting active development and deployment of novel techniques across Iranian state-sponsored groups during this operational period (2026).

Defensive Recommendations

  • Monitor for DLL side-loading activity (T1574.002) by detecting mismatched DLL loads, particularly focusing on legitimate applications loading unexpected DLLs from non-standard directories
  • Implement network monitoring for WebSocket connections and SOCKS5 proxy traffic patterns (T1090.001, T1572) that may indicate tunneling tools like BridgeHead or ArcBridge establishing covert relay channels
  • Detect reconnaissance activities including process enumeration (T1057), screenshot capture (T1113), and collection of NetSetup.log files through endpoint detection rules and file access monitoring
  • Scrutinize job opportunity-themed emails and attachments, especially those redirecting to third-party file-sharing services, and implement email security controls to detect lookalike domains mimicking hiring platforms and videoconferencing services
  • Monitor for HTTPS C2 beaconing patterns (T1071.001) with regular intervals and implement SSL/TLS inspection to detect encrypted command-and-control traffic associated with NightLedger-style backdoors

---

# Geopolitical Context

Geopolitical Context

The campaign attributed to Nimbus Manticore reflects Iran's sustained intelligence collection priorities across the Middle East, Africa, and South Asia. The targeting of government, telecommunications, aviation, and financial sectors in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso is consistent with Tehran's strategic interest in monitoring regional political developments, economic corridors, and potential adversaries. The use of victim networks as covert relay infrastructure—transforming compromised systems into tunneling nodes—suggests operational security concerns and an effort to obscure command-and-control traffic by routing it through trusted regional networks. This approach may also facilitate lateral movement into harder-to-reach targets within the same geopolitical sphere. The focus on telecommunications and aviation sectors aligns with intelligence priorities related to communications interception and tracking of personnel or cargo movements relevant to Iranian regional interests.

State Actor Alignment

Nimbus Manticore is assessed to operate on behalf of the Iranian state, with overlapping reporting linking the group to aliases including GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549. Iran remains subject to comprehensive sanctions by the United States, European Union, and other jurisdictions, including measures targeting cyber actors under Executive Order 13694 and subsequent authorities. The group's operational patterns—including the use of custom tooling such as TWOSTROKE, LIGHTRAIL, and POLLBLEND—are consistent with tasking from Iranian intelligence services, likely the Ministry of Intelligence and Security (MOIS) or Islamic Revolutionary Guard Corps (IRGC). The targeting of SMB and government entities in African nations with limited cyber defense capacity may reflect efforts to exploit permissive environments for intelligence collection and network positioning.

Business Impacty pro region

The geographic spread of victims—from North and East Africa through the Middle East to South Asia—underscores Iran's expanding cyber espionage footprint beyond its immediate neighborhood. For European policymakers, the activity highlights risks to partner nations in Africa and the Middle East, where Iranian intelligence operations may compromise shared telecommunications infrastructure, financial networks, or diplomatic channels. The targeting of aviation and telecommunications sectors poses potential risks to European carriers and service providers operating in or transiting through affected regions. The use of compromised systems as relay infrastructure may also facilitate onward operations against European or Western targets by obscuring the origin of malicious traffic. The campaign's focus on government and SMB environments in countries such as Tanzania and Burkina Faso—where cyber defense capacity is limited—may enable Iran to establish persistent footholds for long-term intelligence collection or influence operations. Regional cybersecurity cooperation mechanisms, including EU-supported capacity-building initiatives, may face challenges in detecting and mitigating such sophisticated, state-backed intrusions.

Forecast

If Nimbus Manticore continues to prioritize telecommunications and government targets in the Middle East and Africa, further compromises of regional infrastructure are likely, potentially enabling Iran to monitor diplomatic communications and economic activity relevant to its strategic interests. If Western or Gulf state adversaries increase pressure on Iran—through sanctions escalation, regional tensions, or cyber operations—the group may expand targeting to include entities in Europe or North America using compromised African and Middle Eastern networks as relay infrastructure. If affected nations lack the capacity to detect and remediate the NightLedger backdoor and associated tunnelers, Iranian intelligence services are likely to maintain long-term access for collection and potential disruptive operations. If international cybersecurity vendors continue to expose Iranian tooling and infrastructure, the group may accelerate development of new custom malware or shift to more aggressive operational security measures, complicating attribution and detection efforts.