Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is actively targeting sectors such as aerospace, aviation, defense, and telecommunications across the Middle East and Africa. This development, reported by Kaspersky, highlights the group’s use of sophisticated spear-phishing campaigns and custom malware to gain unauthorized access and exfiltrate sensitive data. The newly identified tools include the NightLedger backdoor and two WebSocket-based tunnelers, ArcBridge and BridgeHead, designed for covert network access.

Technical Overview

The initial access vector for the malware remains largely unclear; however, the BridgeHead tunneler has been observed in post-exploitation activities in Egypt and Pakistan. These deployments followed targeted spear-phishing campaigns that utilized social engineering tactics, including fake recruitment portals and lookalike videoconferencing pages that directed victims to malicious files.

NightLedger Backdoor

NightLedger is a Windows backdoor that masquerades as SspiCli.dll, employing DLL search-order hijacking techniques. It connects to its command and control (C2) server over HTTPS, periodically sending requests to specific endpoints. The backdoor supports various commands, including gathering user information, executing processes, and taking screenshots, thereby enhancing the group’s espionage capabilities.

BridgeHead and ArcBridge Tunnelers

BridgeHead operates as a WebSocket tunneler, establishing connections that allow the operator to relay traffic through the victim’s machine. It includes mechanisms for proxy authentication and is designed to function within corporate environments. ArcBridge, another tunneling tool, was identified in April 2026 and similarly supports commands for creating proxy sessions and performing DNS resolutions.

Victimology and Implications

Victims of these cyber-espionage operations span several countries, including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The continued evolution of Mirage Kitten’s malware arsenal underscores the persistent threat posed by APT groups in the region, necessitating heightened vigilance and robust cybersecurity measures among targeted sectors.

For further details, refer to the full report by Kaspersky here.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Red Hat releases important libtiff security update for RHEL 8.6 users

Red Hat has announced an important security update for the libtiff library, specifically targeting users of Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission...

Cyber Security Centre warns of increasing complexity in cyber incidents and QR code scams

Cybersecurity incidents are evolving, becoming increasingly intricate and sophisticated, as highlighted in the National Cyber Security Centre's (NCSC) second-quarter report. The report, which focuses...

Core42 Enhances AI Infrastructure for Secure UAE Government Services Deployment

Core42 Enhances AI Infrastructure for Secure UAE Government Services Deployment Core42 is advancing the deployment of secure and scalable AI infrastructure for UAE government services,...

Canada’s Hospital for Sick Children Faces Cyberattack, Employee Data Compromised

Canada’s largest pediatric health center, the Hospital for Sick Children, recently experienced a cybersecurity incident that compromised the personal information of current and former...