Mirage Kitten's New Malware Set NightLedger Backdoor and Two Tunneling Tools
Mirage Kitten’s New Malware Set 🚀
Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is an advanced persistent threat (APT) group focused on cyber-espionage operations against the aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa. They utilize highly targeted spear-phishing campaigns to gain persistent access and exfiltrate sensitive data.
Recent Developments 🔍
During recent threat research, a previously undocumented malware set developed and used by Mirage Kitten was identified. The toolset includes NightLedger, a new Windows backdoor designed for reconnaissance, command execution, file operations, process discovery, and screenshot capture. Additionally, two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, facilitate covert network access and operator-controlled tunneling.
NightLedger is attributed to Mirage Kitten based on code and behavioral similarities to the group’s historical implants. The implant masquerades as SspiCli.dll and is designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. Upon execution, the malicious DLL creates a mutex to enforce a single running instance and periodically contacts its C2 over HTTPS.
Deployment Insights 🌍
BridgeHead was deployed as unbcl.dll in the %LocalAppData%\Microsoft\VisualStudio directory on a machine in Egypt, with similar deployments identified in Pakistan. This malware dynamically loads advapi32.dll, retrieves the current Windows username, and employs techniques to prevent execution in virtual analysis systems.
Victimology 📊
Telemetry indicates that victims have been identified across Middle Eastern and African countries, including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. Mirage Kitten continues to evolve its malware arsenal to support targeted cyber-espionage operations across these regions.
For more detailed information, you can read the full article here.