logo

Mirage Kitten targets Middle East and Africa region with new malware

ID: 26db8abd-30cf-566d-9b54-1b4914599005

STIX ID: report--26db8abd-30cf-566d-9b54-1b4914599005

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Omar Amin, Vasily Berdnikov

...
...

Mirage Kitten (UNC1549) conducted targeted cyber-espionage against aerospace, aviation, defense, and telecommunications organizations across the Middle East, Africa, and Pakistan using spear-phishing and tailored lures; researchers identified a new Windows backdoor named NightLedger and two WebSocket tunneling tools (ArcBridge and BridgeHead) that provide covert proxying and operator-controlled tunneling, with multiple IoCs and victim telemetry included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.