DEV Community

Mark0
Mark0

Posted on

Mirage Kitten targets Middle East and Africa region with new malware

⚠️ Region Alert: UAE/Middle East

Mirage Kitten, an advanced persistent threat (APT) group also known as UNC1549 and Smoke Sandstorm, is currently conducting a cyber-espionage campaign targeting aerospace, defense, and telecommunications sectors across the Middle East and Africa. Recent analysis has uncovered a previously undocumented malware set, including the NightLedger backdoor and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead. These tools facilitate reconnaissance, command execution, and covert network access via operator-controlled SOCKS5 tunneling.

The group utilizes sophisticated initial access vectors, such as highly tailored spear-phishing and DLL search-order hijacking, to deploy their implants. NightLedger provides extensive capabilities including screenshot capture and file operations, while the tunnelers leverage WebSocket protocols to bypass enterprise proxies. The campaign demonstrates a tactical evolution in the group’s infrastructure, shifting from Microsoft Azure toward Cloudflare-backed domains to enhance resilience and complicate attribution efforts.


Read Full Article

Top comments (0)