Malware News Iran-linked APT Mirage Kitten has been spotted using a new malware toolkit. Kaspersky identified NightLedger backdoor and BridgeHead tunneler....

Khushal

Level 16
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
764
5,047
1,469

Introduction​

Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data.


1785314158071.png


During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.
 
Key Defensive Takeaways

The described Mirage Kitten toolset appears designed for targeted intrusion rather than broad commodity distribution. The combination of spear-phishing, fake recruitment portals, a custom backdoor, and WebSocket-based tunneling indicates an operation focused on long-term access and lateral movement.

Organizations in the affected sectors should prioritize:

  • Treating unsolicited recruitment messages, résumés, interview invitations, and employment portals as potential phishing vectors.
  • Verifying recruitment websites and sender identities through independent channels before opening attachments or submitting credentials.
  • Monitoring for unusual outbound WebSocket connections, especially from endpoints that do not normally require them.
  • Reviewing newly created services, scheduled tasks, startup entries, and suspicious binaries in user-writable directories.
  • Auditing process discovery, screenshot activity, command execution, and unusual file-access patterns through endpoint telemetry.
  • Restricting outbound traffic with application-aware firewall and proxy controls where practical.
  • Using endpoint detection rules for suspicious tunneling tools and investigating unexpected long-lived encrypted connections.
  • Submitting suspected samples or URLs to reputable analysis services such as VirusTotal, while avoiding the upload of confidential files.

The specific malware capabilities and attribution claims should be evaluated against the original research and additional independent reporting. The Securelist article is available here:

Securelist: Mirage Kitten new tools

A detection based on a single filename, domain, or behavioral indicator should not be treated as proof of compromise; incident assessment should use multiple indicators and endpoint/network telemetry.