Mirage Kitten Unveils NightLedger Backdoor and WebSocket Tunnelers for Cyber-Espionage in Middle East and Africa

Published:

spot_img

Recent research has unveiled a new set of malware tools attributed to the advanced persistent threat (APT) group known as Mirage Kitten, which is actively targeting sectors such as aerospace, aviation, defense, and telecommunications across the Middle East and Africa. This development, reported by Kaspersky, highlights the group’s use of sophisticated spear-phishing campaigns and custom malware to gain unauthorized access and exfiltrate sensitive data. The newly identified tools include the NightLedger backdoor and two WebSocket-based tunnelers, ArcBridge and BridgeHead, designed for covert network access.

Technical Overview

The initial access vector for the malware remains largely unclear; however, the BridgeHead tunneler has been observed in post-exploitation activities in Egypt and Pakistan. These deployments followed targeted spear-phishing campaigns that utilized social engineering tactics, including fake recruitment portals and lookalike videoconferencing pages that directed victims to malicious files.

NightLedger Backdoor

NightLedger is a Windows backdoor that masquerades as SspiCli.dll, employing DLL search-order hijacking techniques. It connects to its command and control (C2) server over HTTPS, periodically sending requests to specific endpoints. The backdoor supports various commands, including gathering user information, executing processes, and taking screenshots, thereby enhancing the group’s espionage capabilities.

BridgeHead and ArcBridge Tunnelers

BridgeHead operates as a WebSocket tunneler, establishing connections that allow the operator to relay traffic through the victim’s machine. It includes mechanisms for proxy authentication and is designed to function within corporate environments. ArcBridge, another tunneling tool, was identified in April 2026 and similarly supports commands for creating proxy sessions and performing DNS resolutions.

Victimology and Implications

Victims of these cyber-espionage operations span several countries, including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The continued evolution of Mirage Kitten’s malware arsenal underscores the persistent threat posed by APT groups in the region, necessitating heightened vigilance and robust cybersecurity measures among targeted sectors.

For further details, refer to the full report by Kaspersky here.

spot_img

Related articles

Recent articles

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists. The State Security Service of Georgia has initiated a criminal investigation into a purported disinformation...

Untrusted Data Safety

Microsoft Defender’s attack disruption now includes device isolation, a new response action that enhances protection for compromised endpoints. This capability was recently highlighted in...

Snowflake Breach: Hacker Pleads Guilty to Affecting Over 100 Million Records

Snowflake Breach: Hacker Pleads Guilty to Affecting Over 100 Million Records. Connor Riley Moucka has pleaded guilty in a Seattle federal court to multiple...