Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors mirage kitten

Also known as: Smoke Sandstorm, Subtle Snail, UNC1549, tracked as, CVE-2025-2783, APT29, Cozy Bear, CL-STA-1114, TA488, UNK_PitStop, Void Blizzard, Africa, South, Cav3rn

Description

Mirage Kitten, also known as UNC1549, Smoke Sandstorm, Nimbus Manticore and other aliases, has been linked to the Iranian Revolutionary Guard Corps (IRGC) through technical analysis of shared code families and supply‑chain delivery methods. The actor focuses on aerospace, defense, telecommunications, government, financial services and related sectors across the Middle East, Africa and South Asia, using a combination of social engineering and zero‑day exploits such as CVE‑2025‑2783 to gain initial footholds. Operationally, Mirage Kitten leverages highly targeted spear‑phishing vectors—fake plagiarism reports, lookalike video conferencing portals and malicious Office documents—to deliver its modular payload suite. Once inside a network it establishes persistence via Windows services, scheduled tasks and reboot binaries while using anti‑VM checks and memory‑resident execution to evade analysis. The core of the backdoor arsenal is NightLedger, a custom Windows RAT that performs reconnaissance, process discovery, screenshot capture, keylogging and clipboard monitoring. It is complemented by MarkiRAT in office document drops, ArcBridge and BridgeHead WebSocket tunnels for stealthy C2 over Fastly CDN nodes, as well as Psiphon hijacked VPN binaries to further conceal traffic. Supply‑chain compromise via vendor sites and Android implants expands the attack surface. Mirage Kitten’s campaigns emphasize long‑term presence: they minimise disk footprints, embed anti‑analysis logic, use fast‑moving WebSocket tunnels, and occasionally exploit compromised legitimate infrastructure. The resulting threat to critical infrastructure is severe, especially for organizations whose staff are exposed to academic or professional development communications.

Goals & Targeting

Targeted Sectors

Aerospace
Defense
Communications
Government
Financial services
Telecommunications
Healthcare
Aviation
Education
Critical infrastructure
Hospitality
Transportation
Media
Energy
Utilities
Information technology
Retail
Non profit
Manufacturing

Targeted Countries / Regions

Burkina Faso
Egypt
Ethiopia
Jordan
Pakistan
Tanzania, United Republic of
IR
CN
US
RU
UA
PK
EG
IN
SY
TW
BY
BR
KZ
MX
CA

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Mirage Kitten is an advanced Iranian-backed threat actor targeting high‑value sectors in Middle Eastern, African and South Asian countries through sophisticated spear‑phishing campaigns that masquerade as plagiarism reports or academic notifications. The group deploys a modular toolset—including the NightLedger backdoor, custom WebSocket tunnelers ArcBridge/BridgeHead, Psiphon hijack and Android implants—to achieve stealthy persistence, lateral movement, and exfiltration over Fastly CDN‑based command & control channels.

Goals & Targeting

The primary objective of Mirage Kitten is industrial or economic espionage – harvesting sensitive data from aerospace, defense, telecommunications, government, financial and other high‑value sectors that operate in strategic regions. By targeting academics and professionals with plagiarism‑report style phishing, the actor increases its chance of compromise while keeping a low profile. The group prioritises nations along Middle Eastern, African and South Asian lines of interest, particularly Iran’s regional allies and rival states, reflecting a strategic aim to influence geopolitical balance through information theft.

Enhanced Description

Key Capabilities

  • Spear‑phishing using fake plagiarism reports and academic notifications
  • Malicious shortcut (.lnk) attachments that initiate downloads from attacker servers
  • Macro‑laden Office documents dropping backdoors such as MarkiRAT and NightLedger
  • Custom WebSocket tunnelers (ArcBridge, BridgeHead) for covert C2 over Fastly CDN
  • Command & Control infrastructure hosted on Fastly networks
  • Persistence via Windows services, scheduled tasks, reboot binaries and anti‑VM checks
  • Memory‑resident execution to avoid disk-based detection
  • Keylogging and clipboard monitoring capabilities
  • File upload/download functionality within backdoors
  • Remote command execution through the RAT
  • Screenshot capture for reconnaissance
  • Chrome browser shortcut hijacking to launch RAT at startup
  • Hijacking legitimate VPN software (Psiphon) for stealth
  • Android implants targeting mobile devices
  • Credential harvesting with injected keyloggers in popular browsers
  • Supply‑chain delivery via compromised vendor sites

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Discovery
Defense Evasion
Privilege Escalation
Exfiltration

ATT&CK Techniques

T1566.001
T1064
T1053
T1037
T1105
T1219
T1041
T1204.001
T1056.001
T1115
T1059
T1057
T1113
T1071.004

Software / Tooling

Tuoni
MarkiRAT
NightLedger
BridgeHead
ArcBridge
Psiphon

Campaigns & Victims

Mirage Kitten’s campaigns run with high operational tempo, launching fresh spear‑phishing cycles every few weeks to maintain persistence across diverse industries and locations. Victims tend to be organizations with public-facing academic collaborations or financial services linked to international trade. Notable operations include a 2025 deployment targeting universities in the United Arab Emirates via fake plagiarism reports, and a supply‑chain compromise that used a compromised vendor site to deliver NightLedger across multiple African telecom providers. The actor’s use of Fastly CDN nodes for C2 routing is a distinctive pattern, enabling rapid relocation of infrastructure across countries while masking traffic origins.

IOC Patterns

  • malicious PDF disguised as plagiarism report
  • phishing email attachment (.lnk) that triggers malicious shortcut download
  • fake eLibrary website mimicking real homepage
  • Fastly-based URLs used for command and control
  • macro‑laden Office document dropping backdoor
  • keylogger process on Windows systems
  • modified Chrome shortcuts to launch RAT at startup
  • WebSocket‑based C2 tunnelers (ArcBridge, BridgeHead)
  • Windows backdoor files with reconnaissance capabilities

Recommended Actions

  • Deploy robust email filtering and threat intelligence feeds that flag .lnk attachments originating from Fastly CDN domains.
  • Implement strict macro policies in Office applications, allowing only digitally signed scripts.
  • Train employees to verify academic or plagiarism‑report notifications before opening PDFs or links.
  • Enable browser-based security controls to prevent unauthorized shortcut hijacking and keylogger detection.
  • Apply regular OS patching, especially for known CVEs such as CVE‑2025‑2783.
  • Use reputable VPN solutions rather than unverified third‑party binaries like Psiphon, and monitor for anomalies in VPN traffic patterns.
  • Implement endpoint detection and response (EDR) capable of spotting memory‑resident processes and anti‑VM checks.
  • Deploy network segmentation to limit lateral movement once a node is compromised.
  • Periodically audit third‑party vendor access to identify potential supply‑chain vulnerabilities.
  • Employ web filtering to block Fastly CDN IP ranges associated with Mirage Kitten C2 servers.

Suggested Tags

Mirage Kitten
Tuoni
Phishing
Plagiarism
Academic Targeting
Fastly C2
Middle East
Africa
Iranian state-backed actor
Nimbus Manticore
Android implants
NightLedger backdoor
ArcBridge WebSocket C2
Psiphon hijack
Keylogging
Clipboard monitoring
Custom browser hijack
Supply chain delivery

Confidence Assessment

The attribution of Mirage Kitten to the IRGC is supported by multiple independent security reports and shared code families, giving moderate confidence in overall actor identity. However, certain details—such as precise timelines, full extent of supply‑chain compromise mechanisms, and comprehensive mapping of all command & control infrastructure—remain incomplete due to limited disclosure from affected organizations. Consequently, while the technical TTPs exhibit high confidence, strategic motivations and long‑term operational scope should be treated with cautious interpretation.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 8 Email Address 4 Domain 7 Filename 1

References

  1. www.kaspersky.com — Cited by web research for: CVE-2025-2783
  2. thehackernews.com — Cited by web research for: APT29
  3. www.kaspersky.com — Cited by web research for: Payload
  4. gurucul.com — Cited by web research for: Leverage
  5. blog.polyswarm.io — Cited by web research for: Cuba
  6. ai-impact.co.za — Cited by web research for: Manufacturing
  7. https://www.kaspersky.com/about/press-releases/government-and-industrial-sectors-became-the-primary-targets-f — Cited by AI analysis.
  8. https://www.arabianbusiness.com/business/technology/middle-east-digital-spy — Cited by AI analysis.
  9. https://mallory.ai/malware/019fa7d6-92fd-797d-8ef69866d7 — Cited by AI analysis.
  10. https://www.kaspersky.com/about/press-releases/kaspersky-uncovers-new-mirage-kitten-malware-used-in-cyber-espio — Cited by AI analysis.

Intel Summary

14

Techniques

52

Tools

0

Campaigns

36

IOCs

0

Observed Data

8

Tactics

Tags

APT
espionage
government
defense
aerospace
ransomware
Mirage Kitten
Tuoni
Phishing
Plagiarism
Academic Targeting
Fastly C2
Middle East
Africa
Iranian state-backed actor
Nimbus Manticore
Android implants
NightLedger backdoor
ArcBridge WebSocket C2
Psiphon hijack
Keylogging
Clipboard monitoring
Custom browser hijack
Supply chain delivery

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
55%
Added
Jul 28, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.