B
今週中
イラン政府が支援する攻撃グループ「Nimbus Manticore」が、中東、アフリカ、南アジアを標的にした新たな攻撃キャンペーンを展開しています
📌 一言でいうと
イラン政府が支援する攻撃グループ「Nimbus Manticore」が、中東、アフリカ、南アジアを標的にした新たな攻撃キャンペーンを展開しています。攻撃には、偵察やコマンド実行を行う新型バックドア「NightLedger」と、隠密なネットワークアクセスを実現するWebSocketトンネラー「BridgeHead」および「ArcBridge」が使用されています。標的には政府機関、航空、通信、金融などの重要インフラが含まれています。
🔍該当判定
- 中東、アフリカ、南アジア地域の企業・団体で事業を展開している
- 航空、通信、金融業界の組織に所属している
- Windows OSを搭載したPCやサーバーを社内で利用している
- エジプト、ヨルダン、タンザニア、パキスタン、エチオピア、ブルキナファソのいずれかに拠点がある
上記いずれにも該当しない → 静観でOK
✅該当時の対応
WebSocket通信(特に不審な外部ドメインへの接続)の監視強化、不審なWindowsプロセスの検知、およびエンドポイントでの異常なネットワークトンネリング動作の監視を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】イラン系APTグループ「Nimbus Manticore」による新キャンペーンについて
お疲れさまです。Nimbus Manticoreによる新たな攻撃キャンペーンに関する情報共有です。
■ 概要
イラン政府支援の攻撃グループが、新型バックドア「NightLedger」およびWebSocketベースのトンネラー「BridgeHead」「ArcBridge」を用いて、標的組織のシステムを隠密リレーとして利用し、持続的なアクセスを維持する手法が確認されました。
■ 影響範囲
- Windows OS環境
- 主に中東、アフリカ、南アジアの政府・重要インフラ組織
■ 対応手順
1. ネットワークログにおける不審なWebSocket通信(特に未知の外部IP/ドメインへの持続的な接続)の調査
2. エンドポイントにおける未知のバイナリによるトンネリング動作の監視
3. 権限昇格や偵察活動に関連する不審なプロセス実行の検知
■ 参考情報
- Kaspersky Threat Intelligence Report
対応優先度: 中
対応期限: 継続的な監視
お疲れさまです。Nimbus Manticoreによる新たな攻撃キャンペーンに関する情報共有です。
■ 概要
イラン政府支援の攻撃グループが、新型バックドア「NightLedger」およびWebSocketベースのトンネラー「BridgeHead」「ArcBridge」を用いて、標的組織のシステムを隠密リレーとして利用し、持続的なアクセスを維持する手法が確認されました。
■ 影響範囲
- Windows OS環境
- 主に中東、アフリカ、南アジアの政府・重要インフラ組織
■ 対応手順
1. ネットワークログにおける不審なWebSocket通信(特に未知の外部IP/ドメインへの持続的な接続)の調査
2. エンドポイントにおける未知のバイナリによるトンネリング動作の監視
3. 権限昇格や偵察活動に関連する不審なプロセス実行の検知
■ 参考情報
- Kaspersky Threat Intelligence Report
対応優先度: 中
対応期限: 継続的な監視
Subject: [Intel] New Campaign by Iranian APT Group Nimbus Manticore
Dear Team,
We are sharing intelligence regarding a new campaign by the Iranian state-backed actor Nimbus Manticore.
■ Overview
The actor is deploying a new Windows backdoor named "NightLedger" and two custom WebSocket tunnelers, "BridgeHead" and "ArcBridge," to establish covert network access and turn victim systems into relays.
■ Scope
- Windows environments
- Primarily targeting government, aviation, telecom, and financial sectors in the Middle East, Africa, and South Asia.
■ Recommended Actions
1. Monitor network logs for anomalous WebSocket traffic to unknown external destinations.
2. Inspect endpoints for unauthorized tunneling tools or suspicious binary executions.
3. Review system logs for reconnaissance activities associated with the NightLedger backdoor.
■ Reference
- Kaspersky Threat Intelligence Report
Priority: Medium
Deadline: Ongoing Monitoring
Dear Team,
We are sharing intelligence regarding a new campaign by the Iranian state-backed actor Nimbus Manticore.
■ Overview
The actor is deploying a new Windows backdoor named "NightLedger" and two custom WebSocket tunnelers, "BridgeHead" and "ArcBridge," to establish covert network access and turn victim systems into relays.
■ Scope
- Windows environments
- Primarily targeting government, aviation, telecom, and financial sectors in the Middle East, Africa, and South Asia.
■ Recommended Actions
1. Monitor network logs for anomalous WebSocket traffic to unknown external destinations.
2. Inspect endpoints for unauthorized tunneling tools or suspicious binary executions.
3. Review system logs for reconnaissance activities associated with the NightLedger backdoor.
■ Reference
- Kaspersky Threat Intelligence Report
Priority: Medium
Deadline: Ongoing Monitoring