DEV Community

Mark0
Mark0

Posted on

Mirage Kitten targets Middle East and Africa region with new malware

⚠️ Region Alert: UAE/Middle East

The Mirage Kitten APT group, also known as UNC1549 or Smoke Sandstorm, has launched a sophisticated cyber-espionage campaign targeting aerospace, defense, and telecommunications sectors across the Middle East and Africa. This operation utilizes highly tailored spear-phishing lures and fake recruitment portals to deploy a previously undocumented malware toolset. The primary components include the NightLedger backdoor and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, designed for persistence and covert network access.

NightLedger employs DLL search-order hijacking to maintain a low profile while providing operators with capabilities for reconnaissance, screenshot capture, and file manipulation. The accompanying tunnelers, ArcBridge and BridgeHead, facilitate SOCKS5 proxying over WebSockets, allowing the attackers to bypass corporate proxies and relay traffic through infected systems. These tools demonstrate the group's evolving tradecraft, including a shift toward Cloudflare-backed infrastructure and per-target execution checks to evade detection.


Read Full Article

Top comments (0)