An Iranian Crew Is Hunting Aviation in Pakistan and Banks in Burkina Faso. Here Are 32 Indicators, and a Third of Their C2 Is Hosted on Azure.
- Patrick Duggan
- 12 minutes ago
- 5 min read
Kaspersky researchers Omar Amin and Vasily Berdnikov published a report today on new tooling from the Iranian state-nexus cluster tracked as Nimbus Manticore — you will also see it as UNC1549, Mirage Kitten, Smoke Sandstorm, GalaxyGato, and Subtle Snail, because this industry cannot agree on a name for anything. Three previously undocumented tools: a Windows backdoor called NightLedger, and two tunnelers, BridgeHead and ArcBridge.
That is the research. It is theirs, it is good, and we are not going to pretend otherwise.
Here is what we did with it, and why we think it matters more than another writeup of the same report.
Look at who they are hitting
SMBs and government in Egypt. Government in Jordan. Government in Tanzania. Aviation in Pakistan. Telecommunications in Ethiopia. The financial sector in Burkina Faso.
Read that list again with a defender's eye. There is not a Fortune 500 on it. There is not a customer of a major managed detection and response provider on it, at least not many. These are organizations that in most cases do not have a threat intelligence subscription, do not have a SOC running twenty-four hours, and will never appear in a vendor's marquee case study — and they are being worked by a state-resourced crew using tunnelers custom-built to turn their machines into relay infrastructure for the next intrusion.
A telecom operator in Addis Ababa is not a low-value target. It is a low-attention one. Those are different things, and the gap between them is where this kind of operation lives.
So the useful thing to do with a report like this is not to summarize it. It is to get the indicators into a form that the bank in Ouagadougou can actually consume — free, no sales call, no procurement cycle.
What we ingested, and what we did not have
Thirty-two indicators from the report are now in our feed with actor attribution: twenty-one domains, one IP address, and ten file hashes, tagged to Nimbus Manticore and to the specific tool each belongs to. They flow to the public blocklists.
Before we ingested them, we checked. Both NightLedger command-and-control domains — realhealthshop dot com and tjconsultingservices dot com — returned found:false against our corpus. We did not have them. We are not going to dress up an import of somebody else's research as a detection lead, because we published a correction nine days ago for doing exactly that, and the whole point of writing that correction was to not need to write it again.
We did run every indicator through graph correlation, and the honest result is that there is almost nothing there. The one hit worth naming is the IP: 172.86.98.113 has a neighbor in our index at 172.86.110.98, flagged by URLhaus in June serving RemcosRAT out of an open directory. Same /16, different /24. On a hosting range that size, that is a coincidence, not corroboration, and we are saying so rather than dressing it up as a link. Zero cross-feed corroboration is the accurate answer.
Which is itself information. It means this infrastructure is not showing up in the community feeds yet. If you are only consuming free aggregate feeds, you do not have these today.
The tradecraft worth internalizing
NightLedger arrives as a fake system DLL. It masquerades as SspiCli.dll and is placed for DLL search-order hijacking against a legitimate signed binary, AppVShNotify.exe — a Microsoft App-V component. Nothing malicious is dropped that a signature will catch on sight; a trusted executable loads an untrusted library from the wrong directory. It runs a mutex of A8215357-F99A-44FE-BC65-D8F0434B0C03. It supports better than a dozen commands — process execution, directory listing, file upload and download and delete, drive enumeration, screenshots, arbitrary DLL loading, beacon interval changes — and it specifically collects C:\Windows\debug\NetSetup.log, which is the domain-join log. That is a targeted read. Somebody wants to know how the machine is attached to the domain before deciding what to do next.
BridgeHead does the same trick twice more. It ships as unbcl.dll, and its supporting components masquerade as libwinpthread-1.dll and IPHLPAPI.dll. It deploys to %LocalAppData%\Microsoft\VisualStudio\ and to C:\program files (x86)\univpn\promote\ — both paths chosen to look boring. It performs a username-based check before executing, so it declines to run in your sandbox. ArcBridge runs mutex F56E68DA-4A89-46B4-9AC8-7290A7651000.
Initial access is a job offer. Highly tailored employment-themed lures impersonating trusted brands and hiring platforms, plus lookalike videoconferencing pages, redirecting to archives hosted on third-party file-sharing services. Aviation and telecom staff get recruiter mail. It works because it is supposed to work — receiving a recruiter pitch is not an anomaly.
The Azure problem
Count the infrastructure. Of the twenty-one domains in the set, eight are Microsoft-hosted: smartconnect.azurewebsites.net, business-deegital.azurewebsites.net, businessdeegital.azurewebsites.net, neexportfolio.azurewebsites.net, healthcarezoom-centeral.azurewebsites.net, healthcarezoomcenteral.azurewebsites.net, toadreport.azurewebsites.net, business-startup.azurewebsites.net, plus neexportfolio.eastus.cloudapp.azure.com. That is over a third of their command-and-control living inside a cloud tenancy your network already trusts.
This is the part that breaks the common control. Reputation-based blocking of unfamiliar hosting does nothing here, because the hosting is not unfamiliar — it is Azure, and so is half your business. You cannot block azurewebsites.net. Nobody can. Which means the only control that works against this half of their infrastructure is hostname-level: exact-FQDN blocking, TLS SNI inspection, DNS logging you actually read. If your egress policy is "allow known cloud providers," you have allowed this campaign.
The same logic applies to the WebSocket tunnelers generally. BridgeHead and ArcBridge speak WSS on 443 to hosts that look like SaaS. Traffic analysis by port and protocol will not distinguish them from Teams.
What to do
Block the thirty-two indicators. They are in the feed now and the blocklists are free; you do not need to talk to us to pull them.
Hunt for the sideload, because it survives an infrastructure rotation and the domains will not. Look for SspiCli.dll living anywhere other than System32 — specifically alongside AppVShNotify.exe. Look for unbcl.dll, libwinpthread-1.dll, or IPHLPAPI.dll under %LocalAppData%\Microsoft\VisualStudio\ or under a univpn directory. Search for the two mutexes by name. Alert on any read of C:\Windows\debug\NetSetup.log by a process that is not a legitimate domain-join operation — that one is close to free, because almost nothing else touches it.
And if you run aviation, telecom, government, or finance anywhere in the target geography, treat inbound recruiter mail with attachments as a live threat vector this month rather than a generic one.
We hold this at 95 percent. This is Kaspersky's research and their attribution, reported today, and we are distributing it rather than corroborating it — we had none of this infrastructure before this morning and we are not claiming otherwise. What we can say for certain is that thirty-two indicators that were not blockable by a small defender yesterday are blockable today, and for the shops on that target list, that is the entire difference between reading about a campaign and doing something about it.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
