Executive Summary
Mirage Tiger is an elusive cyber threat actor of unknown sophistication and motivation. Limited but concerning information points to potential state-sponsored activity targeting the defense sector in the Middle East and Southeast Asia since at least 2018. While specifics are scarce, recent activity suggests a focus on stealing sensitive data through sophisticated attacks involving Cobalt Strike and Mimikatz.
Goals & Targeting
Mirage Tiger's targeting appears systematic and sector-specific, suggesting strategic intent to compromise defense and technology organizations. This focus may indicate a desire to acquire classified information or disrupt critical systems. The geographic concentration in the Middle East and Southeast Asia could point to regional geopolitical interests or organizational ties to entities active in those regions. Victims are typically high-value targets within these sectors, including government ministries, research institutions, and private defense contractors.
Enhanced Description
Mirage Tiger's activities have been observed primarily in the defense and technology sectors across the Middle East and portions of Southeast Asia. The actor has demonstrated an ability to employ advanced persistent threat (APT) tactics, including spear-phishing campaigns and malware deployments. Notably, Mirage Tiger's operations appear designed to infiltrate systems with high levels of access control, suggesting a focus on exfiltrating sensitive information or intellectual property. While the primary motivation remains unclear— possibilities include state espionage, financial gain, or ideological goals —the level of technical expertise indicates a well-resourced adversary. The actor has maintained operational persistence through 2018 to present, with no evidence of recent activity post-2023.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Mirage Tiger has been linked to operations starting in 2018 and continuing through 2023, with recent activity suggesting a possible decline or shift in tactics. Known campaigns include Operation Trojan Shield, targeting defense contractors, and others focusing on academic research institutions. The actor employs patient hunting strategies, often spending extended periods within networks to gather maximum intelligence before exfiltration. Operational tempo appears deliberate, with campaigns spanning months to achieve deep infiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence. While TTPs and some tooling are known through sample IOCs and linked campaigns, the primary motivation of Mirage Tiger is unclear due to limited open-source reporting. High uncertainty exists regarding long-term strategic goals beyond immediate data exfiltration. Additional intelligence gaps include the extent of their operational infrastructure, potential state sponsorship, and precise targeting criteria.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics