NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
Summary
Hide ▲
Show ▼
The NightLedger, BridgeHead, and ArcBridge toolkit has been deployed in active intrusions to preserve covert access and tunnel operator traffic through victim systems. The set combines a Windows backdoor with WebSocket tunnelers for reconnaissance, command execution, and relay-style network access. The malware also uses DLL side-loading and HTTPS contact to support stealthy execution. The activity spans targets across the Middle East, Africa, and South Asia.
Related Happenings
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
Campaign
H score32
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
How related:
has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
About this happening:
Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
Nimbus Manticore covert access campaign across the Middle East, Africa, and South Asia
CampaignHow related: has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.
About this happening: Nimbus Manticore is running a fresh campaign against entities across the Middle East, Africa, and South Asia, using NightLedger and custom tunnelers to preserve ...
GoSerpent malware activity targeting Southeast Asian entities
Malware Activity
H score26
First: 17.07.2026 11:46
Last: 17.07.2026 11:46
Sources 1
About this happening:
GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
GoSerpent malware activity targeting Southeast Asian entities
Malware ActivityAbout this happening: GoSerpent is being used in cyber attacks against entities in Southeast Asia, with the activity focused on long-term access, intelligence gathering, and data...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
SprySOCKS Windows backdoor activity against government organizations
Malware Activity
H score23
First: 16.06.2026 12:00
Last: 16.06.2026 12:00
Sources 1
About this happening:
SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SprySOCKS Windows backdoor activity against government organizations
Malware ActivityAbout this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...
SPECTRALVIPER DLL sideloading backdoor activity
Malware Activity
H score31
First: 11.06.2026 12:45
Last: 11.06.2026 12:45
Sources 1
About this happening:
The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...
SPECTRALVIPER DLL sideloading backdoor activity
Malware ActivityAbout this happening: The SPECTRALVIPER backdoor was executed on affected Windows hosts through a DLL sideloading chain during October 2025 to March 2026, giving operators a way to run...
Timeline
-
28.07.2026 14:55 2 articles · 1h ago
Nimbus Manticore deploys NightLedger, BridgeHead, and ArcBridge in fresh intrusions
Initial DisclosureNimbus Manticore, an Iranian state-backed group, is tied to fresh intrusions against entities in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, along with other targets across the Middle East, Africa, and South Asia. The campaign uses the NightLedger Windows backdoor and the BridgeHead and ArcBridge WebSocket tunnelers to preserve covert access, with NightLedger launched as a DLL via DLL side-loading and designed for reconnaissance, command execution, file operations, process discovery, and screenshot capture.
Show sources
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays — thehackernews.com — 28.07.2026 14:55
- Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays — thehackernews.com — 28.07.2026 14:55