BridgeHead is a custom Windows WebSocket tunneling utility attributed to the Iranian-aligned cyber-espionage actor Nimbus Manticore, also known as Mirage Kitten, UNC1549, and Smoke Sandstorm. Used during post-exploitation, it establishes an operator-controlled SOCKS5 proxy through a compromised host, relaying TCP traffic between attacker-designated targets and a WebSocket command-and-control channel. This enables covert access to internal network resources from the victim environment. BridgeHead supports enterprise proxy authentication, including Windows single sign-on authentication schemes, allowing it to operate through authenticated corporate proxies. Samples implement victim-specific username checks before activation, restricting execution to intended targets and impeding automated analysis. BridgeHead has been observed in intrusions affecting organizations in Egypt and Pakistan, including aerospace and aviation targets, within a broader espionage campaign against organizations in the Middle East, Africa, and South Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky documented the NightLedger backdoor and ArcBridge and BridgeHead tunneling tools in July 2026.
BridgeHead is listed as one of two custom WebSocket tunnelers in Nimbus Manticore's expanded arsenal.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Mirage Kitten continues to rely on highly targeted spear-phishing, recruitment-themed lures, and fake videoconferencing pages to gain initial access before deploying custom malware.
The phishing activity employed carefully crafted recruitment-themed lures impersonating trusted employers and hiring platforms, alongside lookalike videoconferencing websites that redirected victims to malicious archives hosted on third-party file-sharing services.
The malware dynamically loads advapi32.dll, resolves GetUserNameA ... Notably ... another variant ... shares the same dynamic-resolve stub pattern.
The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection.
NightLedger periodically contacts its C2 over HTTPS ... establishes an HTTPS WebSocket connection ... communicates with businessmixture.com/blog over WSS on port 443
Kaspersky also identified BridgeHead, a custom WebSocket tunneling utility deployed during post-exploitation activity. The malware functions as a full SOCKS5 tunnel proxy, forwarding attacker-controlled traffic through compromised systems...
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tunneling tool previously documented in connection with Mirage Kitten activity; no functional details are provided in this reference.
Custom WebSocket tunneling tool attributed to Nimbus Manticore; no further functionality is described.
A custom WebSocket tunneling tool used to help maintain persistent access to compromised systems.
Custom WebSocket tunneling utility used to support persistent access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.