Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is actively targeting sectors such as aerospace, aviation, defense, and telecommunications across the Middle East and Africa. This development, reported by Kaspersky, highlights the group’s use of sophisticated spear-phishing campaigns and custom malware to gain unauthorized access and exfiltrate sensitive data. The newly identified tools include the NightLedger backdoor and two WebSocket-based tunnelers, ArcBridge and BridgeHead, designed for covert network access.
Technical Overview
The initial access vector for the malware remains largely unclear; however, the BridgeHead tunneler has been observed in post-exploitation activities in Egypt and Pakistan. These deployments followed targeted spear-phishing campaigns that utilized social engineering tactics, including fake recruitment portals and lookalike videoconferencing pages that directed victims to malicious files.
NightLedger Backdoor
NightLedger is a Windows backdoor that masquerades as SspiCli.dll, employing DLL search-order hijacking techniques. It connects to its command and control (C2) server over HTTPS, periodically sending requests to specific endpoints. The backdoor supports various commands, including gathering user information, executing processes, and taking screenshots, thereby enhancing the group’s espionage capabilities.
BridgeHead and ArcBridge Tunnelers
BridgeHead operates as a WebSocket tunneler, establishing connections that allow the operator to relay traffic through the victim’s machine. It includes mechanisms for proxy authentication and is designed to function within corporate environments. ArcBridge, another tunneling tool, was identified in April 2026 and similarly supports commands for creating proxy sessions and performing DNS resolutions.
Victimology and Implications
Victims of these cyber-espionage operations span several countries, including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The continued evolution of Mirage Kitten’s malware arsenal underscores the persistent threat posed by APT groups in the region, necessitating heightened vigilance and robust cybersecurity measures among targeted sectors.
For further details, refer to the full report by Kaspersky here.


