ArcBridge is a custom WebSocket-based tunneling utility used by the Iranian-aligned cyber-espionage actor Mirage Kitten, also tracked as Nimbus Manticore, UNC1549, and Smoke Sandstorm. First identified in April 2026, it enables operators to establish remote proxy or tunnel sessions through compromised systems and perform DNS resolution from those environments. ArcBridge uses embedded communications configuration and single-instance execution controls, supporting covert post-compromise access and operator routing through victim networks. It has been observed in activity targeting organizations in the Middle East and forms part of a bespoke Mirage Kitten toolset alongside the NightLedger backdoor and BridgeHead tunneler. The associated espionage activity has targeted organizations across the Middle East, Africa, and South Asia, including aerospace, aviation, telecommunications, government, and financial-sector entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky documented the NightLedger backdoor and ArcBridge and BridgeHead tunneling tools in July 2026.
ArcBridge is listed as one of two custom WebSocket tunnelers in Nimbus Manticore's expanded arsenal.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection.
NightLedger periodically contacts its C2 over HTTPS ... establishes an HTTPS WebSocket connection ... communicates with businessmixture.com/blog over WSS on port 443
Kaspersky also identified BridgeHead, a custom WebSocket tunneling utility deployed during post-exploitation activity. The malware functions as a full SOCKS5 tunnel proxy, forwarding attacker-controlled traffic through compromised systems...
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling tool previously documented in connection with Mirage Kitten activity; no functional details are provided in this reference.
Custom WebSocket tunneling tool attributed to Nimbus Manticore; no further functionality is described.
A custom WebSocket tunneling tool used to help maintain persistent access to compromised systems.
Custom WebSocket tunneling utility used to support persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.