HomeBusinessKaspersky Uncovers Advanced Mirage Kitten Spyware Campaign Across MEA, Pakistan Among Targets

Kaspersky Uncovers Advanced Mirage Kitten Spyware Campaign Across MEA, Pakistan Among Targets

ISLAMABAD: A new cyber-espionage campaign linked to the advanced persistent threat (APT) group Mirage Kitten has targeted organizations across the Middle East and Africa, including an aviation and aerospace entity in Pakistan, according to cybersecurity researchers.

Kaspersky’s Global Research and Analysis Team (GReAT) revealed that the threat group is using a previously undocumented malware toolkit designed to maintain long-term access to targeted networks and steal sensitive information.

The cybersecurity firm said the campaign involved a new set of malicious tools, including a Windows backdoor named NightLedger, along with two covert tunnelling utilities known as ArcBridge and BridgeHead.

Researchers said NightLedger provides attackers with remote control capabilities, allowing them to execute commands, explore files, transfer data and capture screenshots from compromised systems.

The two tunnelling tools enable attackers to hide their activities by routing malicious traffic through infected machines, making it appear as if the activity is originating from within the victim’s own network.

Kaspersky researchers identified victims of the campaign in several countries, including Egypt, Jordan, Tanzania, Ethiopia and Burkina Faso, involving sectors such as government, telecommunications, finance and small businesses.

The company said BridgeHead was detected during post-compromise activity targeting an aerospace and aviation organization in Pakistan. Researchers observed that the intrusion followed targeted spear-phishing attempts using highly customized lures.

These phishing campaigns included fake recruitment messages impersonating trusted brands and hiring platforms, as well as fraudulent video conferencing pages designed to redirect victims towards malicious archive files hosted on third-party platforms.

Omar Amin, Senior Security Researcher at Kaspersky GReAT, said Mirage Kitten continues to evolve its malware capabilities to support targeted cyber-espionage operations across the Middle East and Africa.

He noted that the group’s continued use of tunnelling utilities demonstrates an increasing focus on bypassing security controls, maintaining hidden access and making detection more difficult for organizations.

Kaspersky urged organizations, particularly those operating critical sectors such as aviation and aerospace, to strengthen cybersecurity monitoring, improve threat detection capabilities and remain alert against sophisticated phishing attempts.

The company recommended adopting advanced security solutions with endpoint detection and response (EDR), extended detection and response (XDR), threat intelligence and incident response capabilities to counter evolving cyber threats.

The discovery highlights the growing cybersecurity challenges facing critical infrastructure as threat actors increasingly rely on advanced malware, social engineering and stealth techniques to target sensitive networks.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular