started · updated
Mirage Kitten APT Deploys New Malware Across Middle East and Africa
Kaspersky's Global Research and Analysis Team (GReAT) has identified a previously undocumented malware suite used by the Mirage Kitten advanced‑persistent threat group. The toolkit, comprising the NightLedger Windows backdoor and two covert tunneling utilities—ArcBridge and BridgeHead—enables attackers to maintain long‑term access to compromised networks and relay traffic through victim machines.
Victims span a range of sectors in the Middle East and Africa, including organisations in Egypt, Jordan and Tanzania, an aviation firm in Pakistan, telecom operators in Ethiopia and financial‑sector entities in Burkina Faso. The campaign, first observed in April 2026, relies on highly tailored spear‑phishing lures such as recruitment‑themed messages and fake video‑conference pages that deliver malicious archives. Kaspersky concludes that Mirage Kitten continues to evolve its malware arsenal to support targeted cyber‑espionage operations across the region.
Entities
Egypt · Kaspersky Global Research and Analysis Team · Mirage Kitten · NightLedger · Pakistan