Contact to us

Kaspersky Exposes Mirage Kitten Cyber-Espionage malware targeting MEA region and Pakistan

Islamabad : Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. Aviation organizations in Pakistan are also among the victims. The malicious tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.

The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organizations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, , telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.

The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioral similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots.

It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim’s machine, as if it originated from inside the victim’s network. This lets them slip past network defenses and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.

While the initial access vector remains unclear in most cases, Kaspersky GReaT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organization in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods. The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.

“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa. Another notable aspect of the campaign is the group’s continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts. Given the persistence and sophistication of these techniques, organizations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.

More details available on Securelist.com.

To stay protected from Mirage Kitten and other APT’s, organizations are advised to remain highly vigilant against the deployment of Mirage Kitten toolset, including NightLedger, ArcBridge and BridgeHead tunneling tools.
To protect the company against a wide range of threats, use solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR for organizations of any size and industry.

Adopt managed security services by Kaspersky such as Compromise Assessment, Managed Detection and Response (MDR) and / or Incident Response, covering the entire incident management cycle – from threat identification to continuous protection and remediation. They help to protect against evasive cyberattacks, investigate incidents and provide additional expertise even if a company lacks cybersecurity workers.

Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organization. Kaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.

Leave a Reply

Your email address will not be published. Required fields are marked *