Securelist
Read post

Mirage Kitten’s new malware set: NightLedger backdoor and two tunneling tools

Kaspersky researchers have uncovered a previously undocumented malware toolset attributed to Mirage Kitten (also known as UNC1549, Smoke Sandstorm, Nimbus Manticore), an Iranian-linked APT group targeting aerospace, aviation, defense, and telecom sectors. The toolset includes NightLedger, a Windows backdoor that uses DLL search-order hijacking via a malicious SspiCli.dll, communicates over HTTPS with C2 servers, and supports 16 commands including reconnaissance, file operations, process management, and screenshot capture. Two WebSocket-based tunneling tools are also detailed: BridgeHead, a SOCKS5 tunnel proxy that handles corporate proxy traversal via NTLM/Negotiate authentication and includes per-target username checks to evade sandbox analysis; and ArcBridge, which supports OPEN and DNS commands for operator-controlled tunneling. Victims were identified in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso. The group is also shifting C2 infrastructure from Microsoft Azure subdomains to Cloudflare-backed domains to complicate attribution. Full IoCs including file hashes and C2 domains are provided.

    #malware
Jul 28•8m read time•From securelist.com
Post cover image
Table of contents
IntroductionTechnical detailsNightLedger backdoorBridgeHead – a WebSocket tunnelerArcBridge: another WebSocket tunneling toolVictimologyConclusionIndicators of compromise
113 Impressions
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard