Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers documented a previously undisclosed malware toolkit attributed to Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) targeting aerospace, aviation, defense, and telecom sectors across the Middle East and Africa. The toolkit comprises NightLedger (a Windows backdoor using DLL search-order hijacking), BridgeHead, and ArcBridge (two custom WebSocket-based SOCKS5 tunnelers with per-target username validation and enterprise proxy traversal logic). Victims span Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, with initial access via spear-phishing using recruitment-themed lures and lookalike videoconferencing pages.