At a glance
| Actor | Mirage Kitten (also UNC1549, Smoke Sandstorm, Nimbus Manticore) |
|---|---|
| Activity | State-aligned cyber espionage and long-term network access |
| Targets | Aviation, defense, telecom, government, and financial sectors |
| Scale | Victims across at least six countries in the Middle East and Africa |
| Attribution | Assessed by multiple firms as an Iran-nexus, IRGC-linked group; no arrests reported |
| Source | Kaspersky Securelist |
TL;DR
Kaspersky has uncovered new Mirage Kitten malware aimed at the Middle East and Africa. The espionage group deployed a fresh Windows backdoor and two covert tunneling tools. Researchers link the activity to the Iran-nexus actor also known as UNC1549.
What happened
Kaspersky researchers found a previously unseen toolset from the group. As they put it, they identified “a previously undocumented malware set developed and used by Mirage Kitten.” The set includes the NightLedger backdoor and two WebSocket tunnelers, ArcBridge and BridgeHead.
The lures follow a familiar script. Operators send recruitment-themed messages that impersonate trusted brands and hiring platforms. Some victims also hit fake videoconferencing pages that push malicious archives. Kaspersky saw the tunneler run after intrusions in Egypt and at a Pakistani aviation firm. The tradecraft matches earlier campaigns flagged by Unit 42 and Check Point Research.
Inside the new toolkit
The NightLedger backdoor
NightLedger gives operators broad control of a Windows host. It runs commands, moves files, lists processes, and captures screenshots. The implant hides by posing as a system library and abusing DLL search-order hijacking. It then beacons to its server over HTTPS. Kaspersky notes strong overlap with an older group implant called TWOSTROKE.
ArcBridge and BridgeHead tunnelers
The two tunnelers turn a victim machine into a quiet relay. Each builds an encrypted WebSocket channel and then acts as a SOCKS5 proxy. Traffic from the operator’s tools appears to come from inside the victim network. BridgeHead also handles corporate proxy logins, which helps it blend into enterprise traffic.
Both tools guard against analysis. They only run when the local username matches a hardcoded value, so sandboxes see nothing. The group has also started shifting from Azure-style subdomains to Cloudflare-backed domains.
Who is behind it
Kaspersky attributes the tools to Mirage Kitten through code and behavior overlap with past implants. The wider industry tracks the same actor as UNC1549, Smoke Sandstorm, and Nimbus Manticore. Google, Check Point, Unit 42, and Microsoft assess it as an Iran-nexus group, widely linked to the IRGC and to the Charming Kitten cluster. That attribution remains an analyst assessment, and no arrests have been announced.
Impact and scale
The victim list spans the Middle East and Africa. Kaspersky reports targets in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The sectors include aviation, telecom, government, and finance. These choices fit a spying mission, since the toolkit favors stealthy access and data theft over noise. The group has long relied on tunneling utilities, and this campaign continues that habit. Other firms tie the targeting to Iranian intelligence priorities.
How to stay protected
Defense starts with the lure. Train staff to treat unexpected recruiter messages with caution. Verify hiring contacts through official channels, and avoid archives pulled from random file-sharing links. Enforce multi-factor authentication on exposed systems.
Detection matters next. Watch for DLL sideloading from odd locations and for unusual outbound WebSocket or proxy traffic. Strong endpoint monitoring and fast isolation limit the damage. For the full indicators and analysis, read the Kaspersky Securelist report. As the team warns, “Mirage Kitten continues to evolve its malware arsenal,” so this Mirage Kitten malware activity is unlikely to stop soon.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.