# Mirage Kitten cyber-espionage campaign

> Live situation record from CLSTR: https://clstr.news/situations/mirage-kitten-cyber-espionage-campaign
> Updated: 2026-08-26T08:18:32.000Z. Sources: 2. Developments: 2.

In April 2026, the Mirage Kitten advanced-persistent threat group began a campaign using a previously undocumented malware suite. This toolkit includes the NightLedger Windows backdoor and two covert tunneling utilities, ArcBridge and BridgeHead, which allow attackers to maintain long-term network access and relay traffic through compromised machines.

By July 2026, researchers identified that the group had targeted various sectors across the Middle East and Africa. Affected entities include organizations in Egypt, Jordan, and Tanzania, an aviation firm in Pakistan, telecom operators in Ethiopia, and financial-sector entities in Burkina Faso. The group utilizes highly tailored spear-phishing lures, such as recruitment-themed messages and fake video-conference pages, to deliver malicious archives for cyber-espionage operations.

## Timeline

### 2026-08-26: Cybersecurity researchers report new malware campaigns targeting US, Israel, and Cambodia

New cyber threats have emerged: Iranian-aligned Screening Serpens is using six new RAT variants to target tech professionals in the US, Israel, and UAE, while Spark RAT targets users in Cambodia.

2 sources. https://clstr.news/cluster/cybersecurity-researchers-report-new-malware-campaigns-targeting-us-israel-and-cambodia

### 2026-07-29: Mirage Kitten APT Deploys New Malware Across Middle East and Africa

Kaspersky uncovers Mirage Kitten's new malware suite—NightLedger, ArcBridge and BridgeHead—used in a cyber‑espionage campaign targeting organisations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia and Burkina F

3 sources. https://clstr.news/cluster/mirage-kitten-apt-deploys-new-malware-across-middle-east-and-africa

---
Cite as: Mirage Kitten cyber-espionage campaign. CLSTR, https://clstr.news/situations/mirage-kitten-cyber-espionage-campaign
