Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Published:

spot_img

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is actively targeting sectors such as aerospace, aviation, defense, and telecommunications across the Middle East and Africa. This development, reported by Kaspersky, highlights the group’s use of sophisticated spear-phishing campaigns and custom malware to gain unauthorized access and exfiltrate sensitive data. The newly identified tools include the NightLedger backdoor and two WebSocket-based tunnelers, ArcBridge and BridgeHead, designed for covert network access.

Technical Overview

The initial access vector for the malware remains largely unclear; however, the BridgeHead tunneler has been observed in post-exploitation activities in Egypt and Pakistan. These deployments followed targeted spear-phishing campaigns that utilized social engineering tactics, including fake recruitment portals and lookalike videoconferencing pages that directed victims to malicious files.

NightLedger Backdoor

NightLedger is a Windows backdoor that masquerades as SspiCli.dll, employing DLL search-order hijacking techniques. It connects to its command and control (C2) server over HTTPS, periodically sending requests to specific endpoints. The backdoor supports various commands, including gathering user information, executing processes, and taking screenshots, thereby enhancing the group’s espionage capabilities.

BridgeHead and ArcBridge Tunnelers

BridgeHead operates as a WebSocket tunneler, establishing connections that allow the operator to relay traffic through the victim’s machine. It includes mechanisms for proxy authentication and is designed to function within corporate environments. ArcBridge, another tunneling tool, was identified in April 2026 and similarly supports commands for creating proxy sessions and performing DNS resolutions.

Victimology and Implications

Victims of these cyber-espionage operations span several countries, including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The continued evolution of Mirage Kitten’s malware arsenal underscores the persistent threat posed by APT groups in the region, necessitating heightened vigilance and robust cybersecurity measures among targeted sectors.

For further details, refer to the full report by Kaspersky here.

spot_img

Related articles

Recent articles

Origin Energy Data Breach 2026: Unauthorized Access Exposes PII of 900,000 Customers

On July 28, 2026, Origin Energy confirmed a significant data breach impacting approximately 900,000 current and former customers. This incident involved unauthorized access and...

Bank of Baroda Reports Cybersecurity Incident Following Alleged Data Theft Claims

Bank of Baroda, one of India's largest state-owned banks, has reported a cybersecurity incident following claims from a threat actor regarding the theft and...

Fairlife resumes US production after ransomware attack, data breach confirmed

USA – The Coca-Cola Company has announced that its dairy subsidiary Fairlife has resumed most production across its four US facilities following a ransomware...

Hackers used autonomous AI agent to conduct cyber-espionage on Thailand’s Ministry of Finance

Researchers from cybersecurity firm Hunt.io have reported a cyber-espionage campaign targeting Thailand's Ministry of Finance, allegedly conducted using an autonomous artificial intelligence agent. The...