Kaspersky researchers have uncovered a previously undocumented malware toolset attributed to Mirage Kitten (also known as UNC1549, Smoke Sandstorm, Nimbus Manticore), an Iranian-linked APT group targeting aerospace, aviation, defense, and telecom sectors. The toolset includes NightLedger, a Windows backdoor that uses DLL search-order hijacking via a malicious SspiCli.dll, communicates over HTTPS with C2 servers, and supports 16 commands including reconnaissance, file operations, process management, and screenshot capture. Two WebSocket-based tunneling tools are also detailed: BridgeHead, a SOCKS5 tunnel proxy that handles corporate proxy traversal via NTLM/Negotiate authentication and includes per-target username checks to evade sandbox analysis; and ArcBridge, which supports OPEN and DNS commands for operator-controlled tunneling. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The group is also shifting C2 infrastructure from Microsoft Azure subdomains to Cloudflare-backed domains to complicate attribution. Full IoCs including file hashes and C2 domains are provided.