Also known as: Smoke Sandstorm, Subtle Snail, UNC1549, tracked as, CVE-2025-2783, APT29, Cozy Bear, CL-STA-1114, TA488, UNK_PitStop, Void Blizzard, Africa, South, Cav3rn
Mirage Kitten, also known as UNC1549, Smoke Sandstorm, Nimbus Manticore and other aliases, has been linked to the Iranian Revolutionary Guard Corps (IRGC) through technical analysis of shared code families and supply‑chain delivery methods. The actor focuses on aerospace, defense, telecommunications, government, financial services and related sectors across the Middle East, Africa and South Asia, using a combination of social engineering and zero‑day exploits such as CVE‑2025‑2783 to gain initial footholds. Operationally, Mirage Kitten leverages highly targeted spear‑phishing vectors—fake plagiarism reports, lookalike video conferencing portals and malicious Office documents—to deliver its modular payload suite. Once inside a network it establishes persistence via Windows services, scheduled tasks and reboot binaries while using anti‑VM checks and memory‑resident execution to evade analysis. The core of the backdoor arsenal is NightLedger, a custom Windows RAT that performs reconnaissance, process discovery, screenshot capture, keylogging and clipboard monitoring. It is complemented by MarkiRAT in office document drops, ArcBridge and BridgeHead WebSocket tunnels for stealthy C2 over Fastly CDN nodes, as well as Psiphon hijacked VPN binaries to further conceal traffic. Supply‑chain compromise via vendor sites and Android implants expands the attack surface. Mirage Kitten’s campaigns emphasize long‑term presence: they minimise disk footprints, embed anti‑analysis logic, use fast‑moving WebSocket tunnels, and occasionally exploit compromised legitimate infrastructure. The resulting threat to critical infrastructure is severe, especially for organizations whose staff are exposed to academic or professional development communications.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Mirage Kitten is an advanced Iranian-backed threat actor targeting high‑value sectors in Middle Eastern, African and South Asian countries through sophisticated spear‑phishing campaigns that masquerade as plagiarism reports or academic notifications. The group deploys a modular toolset—including the NightLedger backdoor, custom WebSocket tunnelers ArcBridge/BridgeHead, Psiphon hijack and Android implants—to achieve stealthy persistence, lateral movement, and exfiltration over Fastly CDN‑based command & control channels.
Goals & Targeting
The primary objective of Mirage Kitten is industrial or economic espionage – harvesting sensitive data from aerospace, defense, telecommunications, government, financial and other high‑value sectors that operate in strategic regions. By targeting academics and professionals with plagiarism‑report style phishing, the actor increases its chance of compromise while keeping a low profile. The group prioritises nations along Middle Eastern, African and South Asian lines of interest, particularly Iran’s regional allies and rival states, reflecting a strategic aim to influence geopolitical balance through information theft.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Mirage Kitten’s campaigns run with high operational tempo, launching fresh spear‑phishing cycles every few weeks to maintain persistence across diverse industries and locations. Victims tend to be organizations with public-facing academic collaborations or financial services linked to international trade. Notable operations include a 2025 deployment targeting universities in the United Arab Emirates via fake plagiarism reports, and a supply‑chain compromise that used a compromised vendor site to deliver NightLedger across multiple African telecom providers. The actor’s use of Fastly CDN nodes for C2 routing is a distinctive pattern, enabling rapid relocation of infrastructure across countries while masking traffic origins.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The attribution of Mirage Kitten to the IRGC is supported by multiple independent security reports and shared code families, giving moderate confidence in overall actor identity. However, certain details—such as precise timelines, full extent of supply‑chain compromise mechanisms, and comprehensive mapping of all command & control infrastructure—remain incomplete due to limited disclosure from affected organizations. Consequently, while the technical TTPs exhibit high confidence, strategic motivations and long‑term operational scope should be treated with cautious interpretation.
No campaigns linked yet.
No observed data linked yet.
14
Techniques
52
Tools
0
Campaigns
36
IOCs
0
Observed Data
8
Tactics