Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is actively targeting sectors such as aerospace, aviation, defense, and telecommunications across the Middle East and Africa. This development, reported by Kaspersky, highlights the group’s use of sophisticated spear-phishing campaigns and custom malware to gain unauthorized access and exfiltrate sensitive data. The newly identified tools include the NightLedger backdoor and two WebSocket-based tunnelers, ArcBridge and BridgeHead, designed for covert network access.

Technical Overview

The initial access vector for the malware remains largely unclear; however, the BridgeHead tunneler has been observed in post-exploitation activities in Egypt and Pakistan. These deployments followed targeted spear-phishing campaigns that utilized social engineering tactics, including fake recruitment portals and lookalike videoconferencing pages that directed victims to malicious files.

NightLedger Backdoor

NightLedger is a Windows backdoor that masquerades as SspiCli.dll, employing DLL search-order hijacking techniques. It connects to its command and control (C2) server over HTTPS, periodically sending requests to specific endpoints. The backdoor supports various commands, including gathering user information, executing processes, and taking screenshots, thereby enhancing the group’s espionage capabilities.

BridgeHead and ArcBridge Tunnelers

BridgeHead operates as a WebSocket tunneler, establishing connections that allow the operator to relay traffic through the victim’s machine. It includes mechanisms for proxy authentication and is designed to function within corporate environments. ArcBridge, another tunneling tool, was identified in April 2026 and similarly supports commands for creating proxy sessions and performing DNS resolutions.

Victimology and Implications

Victims of these cyber-espionage operations span several countries, including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The continued evolution of Mirage Kitten’s malware arsenal underscores the persistent threat posed by APT groups in the region, necessitating heightened vigilance and robust cybersecurity measures among targeted sectors.

For further details, refer to the full report by Kaspersky here.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

CISA Unveils Plan to Enhance Quality of Common Vulnerabilities and Exposures Program Amid Rising CVE Submissions

The Cybersecurity and Infrastructure Security Agency (CISA) has released a white paper outlining its strategy to enhance the Common Vulnerabilities and Exposures (CVE) program,...

Red Hat releases important kernel security update for RHEL 8.6 Advanced and Extended Support

Red Hat has announced a significant kernel security update for its Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update Support and RHEL...

Syria seeks to transform Russian military bases into training centers

Syria is seeking to transform Russian military bases into training centers for its own armed forces, as part of a broader strategy to eliminate...

Armenian National Sentenced to Two Years for Role in Ryuk Ransomware Attacks

An Armenian national has been sentenced to two years in U.S. federal prison after pleading guilty to charges related to multiple ransomware attacks. Karen...