Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Mirage Kitten targets Middle East and Africa region with new malware

d09b14a2fe01c7363ecc56f5d046162c

TLP:CLEAR
Active

MD5 Hash

Description

Mirage Kitten, an advanced persistent threat group also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been observed deploying a previously undocumented malware set targeting aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. The toolset includes NightLedger, a Windows backdoor with reconnaissance, command execution, file operations, process discovery, and screenshot capture capabilities. Two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, enable covert network access and operator-controlled tunneling through victim networks. The group employs highly targeted spear-phishing campaigns, fake recruitment portals, and lookalike videoconferencing pages. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The malware demonstrates operational security through username-based execution checks and advanced proxy traversal capabilities.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Mirage Kitten targets Middle East and Africa region with new malware
Pattern Type
STIX
Confidence
75%
Valid From
Jul 28, 2026 14:00
Total Sightings
0
Added
Jul 28, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of d09b14a2fe01c7363ecc56f5d046162c

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.