Mirage Kitten Deploys New WebSocket‑Tunneling Malware Against Aerospace, Defense & Telecom in the Middle East & Africa
What Happened — Kaspersky’s SecureList reports that the APT group Mirage Kitten (aka UNC1549, Smoke Sandstorm) has fielded a previously undocumented malware suite: the NightLedger Windows backdoor and two WebSocket‑based tunnelers, BridgeHead and ArcBridge. The implants are delivered via highly targeted spear‑phishing lures (recruitment portals, fake video‑conference pages) and have been observed in victim environments in Egypt and Pakistan.
Why It Matters for Compliance & Audit Readiness
- Spear‑phishing‑driven compromises test the effectiveness of SOC 2 CC6.1 (Security) controls around access‑control policies and user‑awareness training.
- The use of custom DLL hijacking and covert tunneling demonstrates the need for continuous evidence collection (process monitoring, file‑integrity) to prove control operation during an audit.
- Detecting and responding to such APT activity aligns with the incident‑response and risk‑assessment criteria required for a defensible SOC 2 audit.
Who Is Affected — Aerospace, aviation, defense, and telecommunications organizations operating in the Middle East and Africa.
Recommended Actions
- Verify that all privileged‑access accounts are covered by a formal security‑awareness program and simulated phishing tests.
- Map DLL‑search‑order hijacking detection to SOC 2 CC6.1 controls; enable endpoint telemetry and continuous monitoring to capture anomalous DLL loads.
- Update WebSocket‑traffic inspection rules and enforce TLS inspection to surface covert tunneling.
Source: SecureList – Mirage Kitten New Tools
Technical Notes —
- Malware: NightLedger (DLL masquerading as SspiCli.dll), BridgeHead & ArcBridge (WebSocket tunnelers).
- Initial Access: Targeted spear‑phishing with recruitment‑themed lures and look‑alike videoconferencing pages.
- C2: HTTPS GET to
realhealthshop.comandtjconsultingservices.com. - Capabilities: Recon, command execution, file ops, screenshot capture, covert network tunneling.
Source: same article