NightLedger is a Windows backdoor attributed to the Iranian-aligned cyber-espionage actor Mirage Kitten, also tracked as Nimbus Manticore, UNC1549, and Smoke Sandstorm. It is used in operations targeting organizations in the Middle East, Africa, and South Asia, including aerospace, aviation, defense, telecommunications, government, financial-sector, and small-business entities. NightLedger masquerades as a legitimate Windows component and executes through DLL search-order hijacking. It communicates with command-and-control infrastructure over HTTPS and supports host and user reconnaissance, directory and logical-drive enumeration, process listing and management, process execution, DLL loading, file download, upload, copying, and deletion, screenshot capture, and collection of Windows diagnostic logs. Its command protocol and development characteristics overlap with the actor's previously observed TWOSTROKE backdoor. NightLedger has been used alongside the BridgeHead and ArcBridge tunneling utilities to support covert, long-term access to compromised environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky documented the NightLedger backdoor and ArcBridge and BridgeHead tunneling tools in July 2026.
The article lists "a Windows backdoor called NightLedger" among Nimbus Manticore's recently expanded malware arsenal.
Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.
Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.
Recent findings also detail the use of a new backdoor called NightLedger and custom WebSocket tunnelers by the group, targeting entities in the Middle East, Africa, and South Asia.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The implant masquerades as SspiCli.dll and abuses DLL search-order hijacking to execute alongside the legitimate Windows binary AppVShNotify.exe.
Command ID Description 1 Gather user and host identity information
Once loaded, NightLedger contacts its C2 infrastructure over HTTPS and supports a broad range of post-compromise activities including... process management...
Once loaded, NightLedger contacts its C2 infrastructure over HTTPS and supports a broad range of post-compromise activities including system reconnaissance...
The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection.
“Recent findings also detail the use of ... custom WebSocket tunnelers by the group.”
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor previously documented in connection with Mirage Kitten activity; no functional details are provided in this reference.
Windows backdoor mentioned only as one component of Nimbus Manticore's broader malware arsenal; no capabilities are provided.
A Windows backdoor mentioned in connection with persistent access to compromised systems.
A newly identified backdoor used by Nimbus Manticore that supports file manipulation and remote command execution, enabling persistent remote access to compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.