Skip to main content
hamster.news

Loading...

SecurelistSecurelist
Jul 28, 2026, 08:05 AM
Read Original

Mirage Kitten targets Middle East and Africa region with new malware

Mirage Kitten targets Middle East and Africa region with new malware
AI Summary

Summary

Mirage Kitten, an APT group targeting aerospace and defense sectors in the Middle East and Africa, has introduced a new malware set comprising the NightLedger backdoor and two WebSocket tunnelers, ArcBridge and BridgeHead. The group uses targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages to deliver the malicious payloads. NightLedger masquerades as SspiCli.dll to hijack AppVShNotify.exe, while BridgeHead operates as a SOCKS5 tunnel proxy to establish covert network access.

Key points

  • NightLedger is a Windows backdoor that masquerades as SspiCli.dll to hijack the legitimate AppVShNotify.exe binary via DLL search-order hijacking.
  • The NightLedger backdoor contacts its C2 over HTTPS at realhealthshop[.]com and uses tjconsultingservices[.]com as a fallback.
  • BridgeHead is a WebSocket-based tunneler deployed as unbcl.dll in Egypt and as libwinpthread-1.dll in a Pakistan-based aerospace organization.
  • The BridgeHead tunneler authenticates via a WebSocket connection to smartconnect.azurewebsites.net and functions as a SOCKS5 proxy.
  • The malware includes ArcBridge, another WebSocket-based tunneler, for operator-controlled network access.

Timeline

28.07.2026

Securelist publishes details on Mirage Kitten's new malware set

NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group.

Omar Amin and Vasily Berdnikov

Background

Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is an APT group focused on cyber-espionage against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Africa.

Why it matters

The introduction of NightLedger and the WebSocket tunnelers demonstrates the group's evolving toolkit to maintain persistent access and exfiltrate sensitive data from high-value targets.

ChatGLM
GLM AIFree
Summary · Aug 2, 2026, 01:13 PM
AI summaries
0 of 15 used
Original Description
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Mirage Kitten targets Middle East and Africa region with new malware | hamster.news