AI Security AI安全 7h ago Updated 1h ago 更新于 1小时前 48

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays Nimbus Manticore部署NightLedger并将受害系统转化为隐蔽中继器

**NightLedger Backdoor:** A new Windows backdoor used by the Iranian state-backed group Nimbus Manticore for reconnaissance, command execution, file operations, process discovery, and screenshot capture. **Custom Tunnelers (BridgeHead & ArcBridge):** Two WebSocket-based tunnelers utilized to maintain covert access and relay traffic through victim systems, effectively turning them into relay nodes for operator-controlled tunneling. **Phishing Initial Access:** The campaign employs highly tailored 伊朗国家支持的黑客组织Nimbus Manticore(别名GalaxyGato等)针对中东、非洲及南亚多国发动新攻击,部署未公开Windows后门NightLedger。 该团伙利用WebSocket隧道工具BridgeHead和ArcBridge将受害系统转化为隐蔽中继节点,实现命令控制与数据外传。 攻击初始访问方式疑似钓鱼邮件伪装成招聘平台或视频会议页面,通过DLL侧加载技术植入恶意载荷。 NightLedger具备完整侦察、文件操作、进程管理及屏幕截图功能,并支持与过往TWOSTROKE类似的HTTPS C2通信模式。 同期曝光的HOLLOWGRAPH malware显示伊朗黑客正滥用

75
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • NightLedger Backdoor: A new Windows backdoor used by the Iranian state-backed group Nimbus Manticore for reconnaissance, command execution, file operations, process discovery, and screenshot capture.
  • Custom Tunnelers (BridgeHead & ArcBridge): Two WebSocket-based tunnelers utilized to maintain covert access and relay traffic through victim systems, effectively turning them into relay nodes for operator-controlled tunneling.
  • Phishing Initial Access: The campaign employs highly tailored phishing lures disguised as job opportunities from trusted brands or lookalike videoconferencing pages to deliver malicious payloads via third-party file-sharing services.

Why It Matters

This article highlights a significant evolution in cyber espionage tactics, specifically the use of legitimate cloud infrastructure (Microsoft Graph API) and novel tunneling techniques to evade detection. For security practitioners, understanding the mechanics of NightLedger and the WebSocket tunnelers is crucial for detecting similar state-sponsored campaigns that blend standard administrative tools with custom malware to maintain persistent access without triggering traditional network alerts.

Technical Details

  • NightLedger Architecture: Launched as a DLL via DLL side-loading, this backdoor contacts external servers over HTTPS to parse and execute commands. Its functionality mirrors previous tools like TWOSTROKE but includes specific capabilities such as collecting C:\Windows\debug\NetSetup.log and updating beacon intervals dynamically. Supported commands include directory listing, file upload/download via HTTP POST, process termination, and screenshot capture.
  • BridgeHead (unbcl.dll): A SOCKS5 tunnel proxy observed in Egypt and Pakistan. It functions as a relay node where the Command and Control (C2) server initiates connections by sending binary commands over WebSockets. The implant forwards traffic between specified targets and the WebSocket channel, making TCP traffic appear to originate from the victim's network.
  • ArcBridge: Another WebSocket tunneling tool used in conjunction with BridgeHead to facilitate covert network access, continuing the threat actor's preference for bespoke tunneling utilities previously seen with LIGHTRAIL and POLLBLEND.
  • Initial Compromise Vector: Attackers use social engineering, specifically job opportunity-themed phishing emails masquerading as hiring platforms or videoconferencing services, to redirect victims to malicious archives hosted on public file-sharing services before delivering the payload.

Industry Insight

Organizations operating in critical sectors within the Middle East, Africa, and South Asia should prioritize monitoring for unusual outbound WebSocket traffic and DLL side-loading behaviors, as these are key indicators of the NightLedger toolkit. Additionally, security teams must implement stricter controls on Microsoft 365 calendar activities and monitor for anomalous API usage patterns, given the increasing trend of adversaries abusing cloud service APIs (as seen in the related HOLLOWGRAPH sample) for command-and-control channels rather than relying solely on traditional C2 servers.

TL;DR

  • 伊朗国家支持的黑客组织Nimbus Manticore(别名GalaxyGato等)针对中东、非洲及南亚多国发动新攻击,部署未公开Windows后门NightLedger。
  • 该团伙利用WebSocket隧道工具BridgeHead和ArcBridge将受害系统转化为隐蔽中继节点,实现命令控制与数据外传。
  • 攻击初始访问方式疑似钓鱼邮件伪装成招聘平台或视频会议页面,通过DLL侧加载技术植入恶意载荷。
  • NightLedger具备完整侦察、文件操作、进程管理及屏幕截图功能,并支持与过往TWOSTROKE类似的HTTPS C2通信模式。
  • 同期曝光的HOLLOWGRAPH malware显示伊朗黑客正滥用Microsoft Graph API将日历事件转化为双工C2通道,体现高级持续性威胁的演进趋势。

为什么值得看

本文揭示了伊朗国家级APT组织在供应链攻击与隐蔽通信领域的最新战术演变,对全球关键基础设施防护体系具有警示意义。其结合社会工程学与合法API滥用的攻击链设计,为网络安全从业者提供了识别新型隐蔽C2行为的重要参考框架。

技术解析

  • NightLedger后门机制:作为全新Windows DLL侧加载后门,支持15类核心操作包括身份收集、远程命令执行、文件上传下载及屏幕捕获,通过HTTPS连接外部C2服务器接收指令,行为特征与历史工具TWOSTROKE高度相似。
  • WebSocket隧道架构:BridgeHead和ArcBridge构成双向流量转发系统,C2服务器主动发起WebSocket二进制指令,植入物仅负责将目标网络流量经受害机器透传至服务端,使攻击流量看似源自内部网络。
  • 初始访问策略:采用定制化钓鱼载荷,伪造知名招聘网站或视频通讯平台页面,诱导用户下载托管于第三方文件共享服务的恶意压缩包,绕过传统安全检测。
  • 关联威胁发现:同期披露的HOLLOWGRAPH malware展示另一维度创新——利用Microsoft Graph API将受害者Outlook日历事件编码为加密任务指令与数据外传通道,所有事件日期设定在2050年以避免被察觉。
  • 地域分布特征:攻击目标覆盖埃及政府机构、约旦坦桑尼亚中小企业、巴基斯坦航空企业、埃塞俄比亚电信运营商及布基纳法索金融机构,呈现明显的区域针对性部署模式。

行业启示

  • 需强化对合法云服务API(如Microsoft Graph)的异常调用监控,特别是非工作时段的大批量日历读写操作可能预示潜伏的C2通道建立。
  • 针对WebSocket协议的深度包检测应纳入企业边界防御体系,重点关注未经授权的长连接通信及二进制指令流特征。
  • 人力资源部门与IT安全团队需协同开展专项钓鱼演练,重点识别伪装成就业机会的网络诱饵,此类社会工程学手段已成为国家级APT组织的首选入口点。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全