Mirage Kitten Malware Targets Middle East and Africa with New Toolset

Mirage Kitten Malware Targets Middle East and Africa with New Toolset

First seen 30 Jul 2026, 13:40 UTC SecurelistStreamlinefeed.Co.Kesecurelist.com 88% similarity 75.5

Article Content

Browse articles
ThreatCluster

The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as government, finance, and telecommunications. The malware utilizes targeted spear-phishing and fake recruitment portals for initial access. NightLedger allows attackers to execute commands, transfer files, and capture screenshots while communicating with command-and-control servers over HTTPS. The attack has impacted organizations in Egypt, Pakistan, Ethiopia, and Burkina Faso, indicating a broad scope of espionage activities. The tools ArcBridge and BridgeHead enhance covert network access, turning compromised systems into relay nodes. This operation aligns with geopolitical interests, as the group is believed to be state-sponsored. The current status indicates ongoing monitoring and analysis by cybersecurity researchers.

Key Points: • Mirage Kitten's new malware suite targets sensitive sectors in the Middle East and Africa. • The NightLedger backdoor enables extensive remote control and data exfiltration capabilities. • The campaign employs sophisticated spear-phishing techniques for initial access.

ThreatCluster AI How this analysis works

Timeline

2026-07-28
Mirage Kitten malware suite identified
Securelist reported on a new malware set including NightLedger and tunneling tools used by Mirage Kitten targeting multiple sectors.
Securelist
2026-07-30
Kaspersky reveals extensive cyber-espionage campaign
Kaspersky's GReAT disclosed the ongoing operations of Mirage Kitten, highlighting its impact on telecommunications and finance in Africa.
Streamlinefeed.Co.Ke

Community

Browse all →