Regions Targeted: Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso
Related Threat Actors: Mirage Kitten
Related Families: NightLedger, BridgeHead, ArcBridge
Key Takeaways
Background
The latest activity attributed to Mirage Kitten reflects an evolution of the group's existing cyber-espionage capabilities rather than an entirely new campaign. Instead of relying on commodity malware, the operators continue developing custom implants tailored for reconnaissance, command execution, and covert communications. Particularly notable is the use of victim-specific execution controls, WebSocket-based tunneling, and infrastructure that increasingly leverages Cloudflare-backed domains instead of Microsoft Azure-hosted services. These developments suggest the group is refining its operational security while maintaining a strategic focus on long-term intelligence collection against high-value regional targets. Organizations operating within government, defense, aerospace, aviation, telecommunications, and other strategically significant sectors should expect continued investment in bespoke tooling from Mirage Kitten and similar state-sponsored threat actors. Kaspersky reported on this activity.
Although Kaspersky was unable to definitively identify the initial access vector for every intrusion, investigators observed BridgeHead deployed following targeted spear-phishing activity against organizations in Egypt and a Pakistan-based aerospace and aviation organization. The phishing activity employed carefully crafted recruitment-themed lures impersonating trusted employers and hiring platforms, alongside lookalike videoconferencing websites that redirected victims to malicious archives hosted on third-party file-sharing services. This approach aligns with previously documented Mirage Kitten tradecraft emphasizing highly selective social engineering rather than indiscriminate phishing campaigns.
Malware Analysis
The centerpiece of the campaign is NightLedger, a newly identified Windows backdoor attributed to Mirage Kitten based on code and behavioral similarities with the group's historical malware. The implant masquerades as SspiCli.dll and abuses DLL search-order hijacking to execute alongside the legitimate Windows binary AppVShNotify.exe. Once loaded, NightLedger contacts its C2 infrastructure over HTTPS and supports a broad range of post-compromise activities including system reconnaissance, process execution, directory enumeration, screenshot capture, file upload and download, process management, and collection of Windows diagnostic logs such as NetSetup.log. The malware communicates using custom-delimited C2 responses, demonstrating continued reuse and refinement of techniques previously observed in the group's TWOSTROKE backdoor.
Kaspersky also identified BridgeHead, a custom WebSocket tunneling utility deployed during post-exploitation activity. The malware functions as a full SOCKS5 tunnel proxy, forwarding attacker-controlled traffic through compromised systems while supporting enterprise proxy authentication using Windows single sign-on credentials. Before activating, BridgeHead validates that it is executing under a specific Windows username, indicating the malware is customized for individual victims and designed to hinder automated malware analysis. Researchers observed a second BridgeHead variant implementing the same victim-specific execution logic while communicating with different C2 infrastructure, further highlighting Mirage Kitten's tailored operational approach.
Researchers also documented ArcBridge, a second WebSocket-based tunneling utility first identified in April 2026. Like NightLedger, ArcBridge employs a unique mutex to prevent multiple instances while embedding a configuration block containing C2 host information, communication settings, and an implant identifier directly within the malware. The utility enables operators to establish remote proxy sessions and perform DNS resolution through compromised hosts, expanding Mirage Kitten's ability to conduct covert post-compromise operations within victim environments.
Who is Mirage Kitten?
Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is an advanced persistent threat (APT) group known for conducting long-term cyber-espionage operations targeting organizations across the Middle East and Africa. The group primarily focuses on aerospace, aviation, defense, telecommunications, government, and other strategically significant sectors through highly tailored spear-phishing campaigns, custom malware, and operational techniques designed to facilitate long-term intelligence collection while minimizing detection. Rather than pursuing financially motivated attacks, Mirage Kitten is associated with carefully targeted intrusions intended to establish and maintain access to high-value organizations. Recent activity indicates the group continues expanding its bespoke malware ecosystem while preserving the victim-specific operational approach that has characterized previous campaigns.
Analyst Commentary
Mirage Kitten's latest campaign illustrates the continued maturation of state-sponsored cyber-espionage operations through modular, purpose-built malware rather than monolithic implants. By separating reconnaissance, command execution, and network tunneling into specialized components, the operators increase operational flexibility while complicating detection and incident response efforts. The use of victim-specific execution logic, enterprise-aware proxy authentication, and encrypted WebSocket communications further demonstrates an emphasis on maintaining long-term access within targeted environments while reducing exposure during malware analysis.
Equally significant is the apparent evolution of the group's C2 infrastructure. Mirage Kitten is gradually shifting portions of its infrastructure away from Microsoft Azure-hosted services toward Cloudflare-backed domains. This transition reflects an ongoing effort to improve operational resilience while making network-based detection and attribution more challenging.
For defenders, campaigns such as this one reinforce the importance of identifying malicious activity based on behavior rather than relying exclusively on signatures or static indicators. Custom malware, victim-specific payloads, and evolving C2 infrastructure can significantly reduce the effectiveness of traditional detection methods. Organizations operating within aerospace, aviation, defense, telecommunications, government, and financial sectors should prioritize behavioral analytics, threat intelligence, and continuous monitoring capable of identifying anomalous DLL loading, encrypted WebSocket communications, and post-exploitation tunneling activity before attackers can establish long-term access.
PolySwarm helps security teams strengthen these efforts by aggregating threat intelligence and malware analysis from dozens of independent detection engines into a single platform, enabling analysts to identify emerging malware families, validate suspicious files against diverse detection methodologies, and gain earlier visibility into evolving threats that may not yet be consistently identified by any single security vendor. This diversity of analysis provides additional context for rapidly changing espionage campaigns, helping defenders make more informed detection and response decisions as threat actors continue to refine their tooling.
IOCs
PolySwarm has a sample of NightLedger.
24771d0a69e442b9493ab1406e0253be1acd31d83f593177fd736f7f6d629ed9
Click here to view all samples of NightLedger in our PolySwarm portal.
Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.
Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.