Kaspersky researchers say the threat group known as Mirage Kitten is using a newly documented malware set in operations targeting the Middle East and Africa. The actor is also tracked under the names UNC1549, Smoke Sandstorm, and Nimbus Manticore, linking the findings to a broader body of cyber-espionage activity.
According to the report, the newly identified toolset includes the NightLedger backdoor as well as two tunneling tools called ArcBridge and BridgeHead. In general terms, a backdoor can help attackers maintain covert access, while tunneling tools are often used to move traffic through infected systems in a less visible way.
The research adds fresh detail to how Mirage Kitten appears to operate and expands public knowledge of malware previously not documented. The available description ties the group to cyber-espionage campaigns and indicates a focus on organizations in the region, including activity touching sectors such as aerospace and aviation.
The disclosure is significant because it gives defenders new malware names and aliases to watch for when tracking Mirage Kitten activity. It also underscores continued concern around advanced persistent threat operations aimed at strategic targets across the Middle East and Africa.