Verticals Targeted: Fintech, Aviation, Aerospace
Regions Targeted: Middle East, Africa, Egypt, Ethiopia, Afghanistan
Related Families: NodeRabbit, PollCat
The Job Offer Has Claws: Mirage Kitten Deploys NodeRabbit and PollCat
Sep 8, 2026, 2:00:19 PM / by The Hivemind posted in Threat Bulletin, Nimbus Manticore, UNC1549, Mirage Kitten, Smoke Sandstorm, NodeRabbit malware, PollCat malware, Mirage Kitten APT
Mirage Kitten Deploys NightLedger Backdoor in Espionage Campaign Targeting the Middle East and Africa
Jul 31, 2026, 1:58:15 PM / by The Hivemind posted in Threat Bulletin, Spear Phishing, Nimbus Manticore, cyber espionage, aerospace cybersecurity, UNC1549, Mirage Kitten, NightLedger, ArcBridge, Smoke Sandstorm, WebSocket tunneling, BridgeHead
Verticals Targeted: Aerospace, Aviation, Defense, Telecommunications, Government, Financial Services, SMBs
Regions Targeted: Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso
Related Threat Actors: Mirage Kitten
Related Families: NightLedger, BridgeHead, ArcBridge
Executive Summary
New research details the continued evolution of Mirage Kitten, an advanced persistent threat (APT) group conducting cyber-espionage operations across the Middle East and Africa. The campaign introduces three previously undocumented malware families, NightLedger, BridgeHead, and ArcBridge, that provide reconnaissance, command execution, covert tunneling, and persistent post-compromise access capabilities. The findings demonstrate Mirage Kitten's continued investment in bespoke malware development and operational security to support long-term intelligence collection.
Iranian Threat Actor Nimbus Manticore Expands Wartime Cyber Operations with AI-Assisted Malware and SEO Poisoning
Jun 1, 2026, 3:01:24 PM / by The Hivemind posted in Threat Bulletin, IRGC cyber operations, Nimbus Manticore, MiniJunk malware, UNC1549, MiniFast malware, AppDomain Hijacking, Iranian cyber threats, aviation cyber threats, SEO poisoning
Verticals Targeted: Aviation, Defense, Telecommunications, Software Development, Government
Regions Targeted: US, Israel, UAE, Saudi Arabia, Western Europe, Middle East, Africa
Related Threat Actors: Nimbus Manticore
Related Families: MiniJunk, MiniFast
Executive Summary
IRGC-affiliated threat actor Nimbus Manticore significantly expanded its operational capabilities during the ongoing 2026 Middle East conflict, introducing a new backdoor dubbed MiniFast alongside advanced delivery mechanisms including AppDomain Hijacking, scheduled task abuse, and SEO poisoning. The campaign has targeted aviation, software, defense, and telecommunications organizations across the US, Europe, and the Middle East using phishing lures, Trojanized software installers, and stealth-focused persistence techniques designed to blend into legitimate enterprise activity.
Nimbus Manticore’s Evolving Cyberespionage Campaign
Sep 29, 2025, 2:53:45 PM / by The Hivemind posted in Threat Bulletin, Telecommunications, Spear Phishing, malware obfuscation, DLL sideloading, Iranian APT, Nimbus Manticore, MiniJunk, MiniBrowse, defense manufacturing
Verticals Targeted: Defense Manufacturing, Telecommunications, Aerospace
Regions Targeted: Western Europe, Middle East
Related Families: MiniJunk, MiniBrowse