Kaspersky uncovers new malware set from Mirage Kitten
Kaspersky researchers have announced the discovery of NightLedger, ArcBridge, and BridgeHead tools used in targeted cyber espionage operations across the Middle East and Africa.
12punto
The Kaspersky Global Research and Analysis Team (GReAT) has announced the detection of a previously undocumented malware set used by the advanced persistent threat (APT) group known as “Mirage Kitten.”
According to findings shared at the company’s annual Cybersecurity Weekend event for the Middle East, Turkey, and Africa (META) region, the toolset was used in targeted cyber espionage activities to maintain long-term access to victim networks and exfiltrate sensitive data.
Researchers stated that the campaign targeted various institutions and sectors across the Middle East and Africa. Findings included organizations in Egypt, SMEs and public institutions in Jordan and Tanzania, aviation organizations in Pakistan, telecommunications companies in Ethiopia, and financial sector entities in Burkina Faso.
WHAT DOES THE NEW TOOLSET DO?
According to Kaspersky, the set consists of three specific tools. At the center of these is NightLedger, a new backdoor targeting Windows systems. Researchers linked this tool to Mirage Kitten due to its code structure and behavioral characteristics.
NightLedger provides attackers with remote control over compromised systems. Through this, operations such as executing commands, viewing and transferring files, and taking screenshots can be performed.
ArcBridge and BridgeHead, which are included in the set, are defined as covert tunneling tools. These tools can use a compromised computer as an intermediate node for attacker traffic, making activities appear as if they are originating from within the victim's network. This method makes it easier to bypass network security controls and hide access for longer periods.
Kaspersky reported that one of the tools was detected in April 2026 during activities targeting victims in the Middle East. BridgeHead was observed in victim environments in Egypt and in the systems of an aerospace organization in Pakistan during activities conducted after the initial breach.
The exact method of initial access in many cases remains unconfirmed. However, researchers reported finding traces of targeted phishing attempts consistent with the group's known methods in some of the incidents examined. These attempts featured recruitment-themed messages, content mimicking trusted brands and platforms, fake video conferencing pages, and malicious archive files hosted on third-party file-sharing services.
Omar Amin, a Senior Security Researcher at Kaspersky GReAT, stated that the latest findings show Mirage Kitten continues to develop its malware capabilities to support its targeted operations in the Middle East and Africa. Amin pointed out that tunneling techniques allow attackers to bypass network controls and make their detection more difficult.
The company recommended that organizations conduct active threat hunting against such threats, monitor indicators related to backdoor and tunneling tools, leverage threat intelligence, and strengthen their detection and response capabilities.