Mirage Kitten targets Middle East and Africa region with new malware

Summary
Mirage Kitten, an APT group targeting aerospace and defense sectors in the Middle East and Africa, has introduced a new malware set comprising the NightLedger backdoor and two WebSocket tunnelers, ArcBridge and BridgeHead. The group uses targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages to deliver the malicious payloads. NightLedger masquerades as SspiCli.dll to hijack AppVShNotify.exe, while BridgeHead operates as a SOCKS5 tunnel proxy to establish covert network access.
Key points
- NightLedger is a Windows backdoor that masquerades as SspiCli.dll to hijack the legitimate AppVShNotify.exe binary via DLL search-order hijacking.
- The NightLedger backdoor contacts its C2 over HTTPS at realhealthshop[.]com and uses tjconsultingservices[.]com as a fallback.
- BridgeHead is a WebSocket-based tunneler deployed as unbcl.dll in Egypt and as libwinpthread-1.dll in a Pakistan-based aerospace organization.
- The BridgeHead tunneler authenticates via a WebSocket connection to smartconnect.azurewebsites.net and functions as a SOCKS5 proxy.
- The malware includes ArcBridge, another WebSocket-based tunneler, for operator-controlled network access.
Timeline
Securelist publishes details on Mirage Kitten's new malware set
“NightLedger is a recently identified Windows backdoor that we attribute to Mirage Kitten based on code and behavioral similarities to the historical implants developed and used by the group.”
Background
Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is an APT group focused on cyber-espionage against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Africa.
Why it matters
The introduction of NightLedger and the WebSocket tunnelers demonstrates the group's evolving toolkit to maintain persistent access and exfiltrate sensitive data from high-value targets.