news.mlab.sh
Back to the feed
threat-intel

Mirage Kitten targets Middle East and Africa region with new malware

High
Summary

The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, telecommunications, and finance, using a sophisticated combination of spear-phishing, fake recruitment portals, and custom malware. Their primary tool is the NightLedger backdoor, a DLL-hijacking technique designed to gain persistent access to systems, alongside tunneling utilities like ArcBridge and BridgeHead. The group continues to evolve its tactics, moving away from Microsoft Azure infrastructure in favor of Cloudflare-backed domains to evade detection. Recent analysis reveals a shift towards more targeted malware, incorporating a per-target username check to limit execution to specific machines, and a reliance on tunneling to bypass network defenses.

The advanced persistent threat (APT) group Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is actively engaged in cyber-espionage operations across the Middle East and Africa. They are leveraging highly targeted spear-phishing campaigns, utilizing fake recruitment portals, and deploying custom multi-stage malware to maintain persistent access and exfiltrate sensitive data. Recent threat research has uncovered a previously undocumented malware set developed and used by Mirage Kitten, including the NightLedger backdoor and tunneling utilities ArcBridge and BridgeHead.

Mirage Kitten’s primary tool, NightLedger, is a recently identified Windows backdoor attributed to the group. This backdoor masquerades as `Sspicli.dll` and is designed to hijack DLL search order, targeting a legitimate `AppVShNotify.exe` binary. By importing `RPCRT4.dll`, NightLedger delays-loads `Sspicli.dll` when an RPC API is invoked, allowing a co-located malicious DLL to be loaded while forwarding expected exports to the legitimate DLL. The implant creates a mutex (`A8215357-F99A-44FE-BC65-D8F0434B0C03`) to enforce single-running instance and periodically contacts its C2 over HTTPS, using `realhealthshop[.]com` and `tjconsultingservices[.]com` as fallback C2 addresses. NightLedger supports commands returned via HTTP POST requests to `/wsdefvvbnhyuijkplmbgfrtt` and `/edfcvfgbhnjmkqwasderfgg`.

Alongside NightLedger, Mirage Kitten utilizes tunneling utilities to further obfuscate their activity. ArcBridge is a WebSocket tunneling tool that creates a mutex (`F56E68DA-4A89-46B4-9AC8-7290A7651000`) and communicates over a WebSocket channel, awaiting server-side control messages. It supports commands and dynamically resolves a C2 host and port. BridgeHead is another WebSocket tunneling tool, identified in April 2026, which utilizes `unbcl.dll` and `libwinpthread-1.dll`. BridgeHead employs a per-target username check by retrieving the current Windows username and searching for a specific substring within it, preventing execution on machines without the correct username.

Victimology includes countries such as Egypt, Jordan, Tanzania, Ethiopia, and Burkina Faso, targeting sectors including aerospace, aviation, telecommunications, and financial institutions. The group is increasingly moving away from Microsoft Azure infrastructure, utilizing Cloudflare-backed domains to complicate attribution and maintain resilient command-and-control communications. Indicators of compromise (IOCs) are available to customers of the Threat Intelligence Reporting service.

**Additional IOCs:**

  • **File Hashes:**
  • NightLedger backdoor: `A239E655709A2518DD0B7BDBED163679`
  • ArcBridge WebSocket tunneling tool: `5FA15EF96808EA82F0A6176F0BB4B386`, `42F847597109DA2A220391BB09D00676`, `AFB1C1583606599C7272CFB33CC6F498`, `6038D42AF0AFFD1FB263F470C0956F6B`, `AE628EFA305387B633DCE82F9364875B`, `F7D36CC5904A53252D2BB3D21615134F`
  • **Domains and IPs:**
  • `smartconnect[.]azurewebsites[.]net`
  • `businessmixture[.]com`
  • `global-reds[.]com`
  • `maadinglobal[.]com`
  • `business-deegital[.]azurewebsites[.]net`
  • `businessstartup[.]azurewebsites[.]net`
  • `neexportfolio[.]azurewebsites[.]net`
  • `neexportfolio[.]com`
  • `neexportfolio[.]eastus[.]cloudapp[.]azure[.]com`
  • `172[.]86[.]98[.]113`
  • `aecert[.]org`
  • `realhealthshop[.]com`
  • `tjconsultingservices[.]com`
  • `thehealth-life[.]com`
  • `business-startup[.]azurewebsites[.]net`
  • `businessstartup[.]azurewebsites[.]net`
  • `toadreport[.]azurewebsites[.]net`
  • `business-deegital[.]azurewebsites[.]net`
  • `businessstartup[.]azurewebsites[.]net`
  • `business-deegital[.]azurewebsites[.]net`
Read the full article at Securelist