Mirage Kitten’s New Malware Toolkit Targets Aerospace and Defense Across Middle East and Africa

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • New toolset: Mirage Kitten uses three previously undocumented tools – NightLedger backdoor, BridgeHead, and ArcBridge.
  • Sectors targeted: Aerospace, aviation, defense, and telecommunications across the Middle East and Africa.
  • Infrastructure shift: The group is moving away from Microsoft Azure subdomain infrastructure toward Cloudflare-backed domains.

Mirage Kitten, the advanced persistent threat (APT) group also tracked as UNC1549, TA455, Smoke Sandstorm, and Nimbus Manticore, was observed using a previously unseen malware set: NightLedger, a Windows backdoor, and WebSocket-based tunnelers BridgeHead and ArcBridge.

Mirage Kitten Deploys New Espionage Toolset

Kaspersky's Securelist researchers identified three new tools developed by the APT

Commands NightLedger supports | Source: Kaspersky
Commands NightLedger supports | Source: Kaspersky

NightLedger Backdoor and BridgeHead Tunneler

NightLedger masquerades as SspiCli.dll and is built for DLL search-order hijacking against a legitimate AppVShNotify.exe binary. It contacts its command-and-control (C2) server over HTTPS at realhealthshop[.]com, with tjconsultingservices[.]com serving as a fallback, and supports commands ranging from screenshot capture to collecting the NetSetup.log file. Its command structure resembles the TWOSTROKE backdoor previously attributed to the same group. 

BridgeHead, deployed as unbcl.dll and libwinpthread-1.dll, checks for a specific lowercased Windows username before activating, then establishes an HTTPS WebSocket connection and functions as a full SOCKS5 tunnel proxy. 

ArcBridge, first observed in April 2026, relies on an embedded configuration block and supports OPEN and DNS commands.

Victimology and Infrastructure

Mirage Kitten focuses on cyber-espionage against organizations, relying on spear-phishing campaigns consistent with tradecraft publicly reported by Unit 42 and Check Point Research, fake recruitment portals, and videoconferencing pages that redirected to malicious archives on third-party file-sharing services. Domains and IPs include:

Kaspersky's telemetry identified victims in Egypt, alongside SMB and government environments in Jordan and Tanzania, an aviation organization in Pakistan, telecommunications companies in Ethiopia, and financial-sector entities in Burkina Faso.

The report says the group continues to lean on tunneling utilities while gradually shifting from Microsoft Azure subdomain-style infrastructure toward Cloudflare-backed domains. Mandiant assesses that it is affiliated with Iran and overlaps with other Iranian clusters. 

A May analysis outlined that Iran-linked MuddyWater group breached organizations in nine countries in Q1 2026, including a major electronics maker. 


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: