Streamlinefeed.Co.Ke Mirage Kitten Malware Targets Middle East and Africa with New Toolset
Article Content
- •Mirage Kitten's new malware suite targets sensitive sectors in the Middle East and Africa.
- •The NightLedger backdoor enables extensive remote control and data exfiltration capabilities.
- •The campaign employs sophisticated spear-phishing techniques for initial access.
The Mirage Kitten APT group has deployed a sophisticated malware suite, including the NightLedger backdoor, across the Middle East and Africa. This campaign has successfully infiltrated sensitive sectors such as government, finance, and telecommunications. The malware utilizes targeted spear-phishing and fake recruitment portals for initial access. NightLedger allows attackers to execute commands, transfer files, and capture screenshots while communicating with command-and-control servers over HTTPS. The attack has impacted organizations in Egypt, Pakistan, Ethiopia, and Burkina Faso, indicating a broad scope of espionage activities. The tools ArcBridge and BridgeHead enhance covert network access, turning compromised systems into relay nodes. This operation aligns with geopolitical interests, as the group is believed to be state-sponsored. The current status indicates ongoing monitoring and analysis by cybersecurity researchers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Mirage Kitten, NightLedger and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…