HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Mirage Kitten Deploys New WebSocket‑Tunneling Malware Against Aerospace, Defense & Telecom in Middle East & Africa

Mirage Kitten has fielded a new Windows backdoor (NightLedger) and two WebSocket tunnelers (BridgeHead, ArcBridge) delivered via spear‑phishing lures targeting aerospace, defense and telecom firms. The campaign highlights gaps in security‑awareness and continuous monitoring required for SOC 2 readiness.

LiveThreat™ Intelligence · 📅 July 28, 2026· 📰 securelist.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
securelist.com

Mirage Kitten Deploys New WebSocket‑Tunneling Malware Against Aerospace, Defense & Telecom in the Middle East & Africa

What Happened — Kaspersky’s SecureList reports that the APT group Mirage Kitten (aka UNC1549, Smoke Sandstorm) has fielded a previously undocumented malware suite: the NightLedger Windows backdoor and two WebSocket‑based tunnelers, BridgeHead and ArcBridge. The implants are delivered via highly targeted spear‑phishing lures (recruitment portals, fake video‑conference pages) and have been observed in victim environments in Egypt and Pakistan.

Why It Matters for Compliance & Audit Readiness

  • Spear‑phishing‑driven compromises test the effectiveness of SOC 2 CC6.1 (Security) controls around access‑control policies and user‑awareness training.
  • The use of custom DLL hijacking and covert tunneling demonstrates the need for continuous evidence collection (process monitoring, file‑integrity) to prove control operation during an audit.
  • Detecting and responding to such APT activity aligns with the incident‑response and risk‑assessment criteria required for a defensible SOC 2 audit.

Who Is Affected — Aerospace, aviation, defense, and telecommunications organizations operating in the Middle East and Africa.

Recommended Actions

  • Verify that all privileged‑access accounts are covered by a formal security‑awareness program and simulated phishing tests.
  • Map DLL‑search‑order hijacking detection to SOC 2 CC6.1 controls; enable endpoint telemetry and continuous monitoring to capture anomalous DLL loads.
  • Update WebSocket‑traffic inspection rules and enforce TLS inspection to surface covert tunneling.

Source: SecureList – Mirage Kitten New Tools

Technical Notes

  • Malware: NightLedger (DLL masquerading as SspiCli.dll), BridgeHead & ArcBridge (WebSocket tunnelers).
  • Initial Access: Targeted spear‑phishing with recruitment‑themed lures and look‑alike videoconferencing pages.
  • C2: HTTPS GET to realhealthshop.com and tjconsultingservices.com.
  • Capabilities: Recon, command execution, file ops, screenshot capture, covert network tunneling.

Source: same article

📰 Original Source
https://securelist.com/mirage-kitten-new-tools/120811/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →