Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore) deployed custom malware including the NightLedger backdoor and the ArcBridge and BridgeHead WebSocket tunnelers to conduct targeted espionage against aerospace, aviation, defense, and telecom victims in the Middle East, Europe, and Africa. The campaign used spear-phishing, fake recruitment portals, and proxy-aware tunneling infrastructure to maintain access, exfiltrate data, and hide command-and-control traffic. #MirageKitten #UNC1549 #NightLedger #ArcBridge #BridgeHead
Keypoints
- Mirage Kitten is a long-running APT group focused on cyber-espionage against aerospace, aviation, defense, and telecommunications targets.
- The group used targeted spear-phishing with recruitment-themed lures and lookalike videoconferencing pages to deliver malicious archives.
- NightLedger is a newly identified Windows backdoor that supports reconnaissance, process execution, file operations, screenshot capture, DLL loading, and data theft.
- NightLedger uses DLL search-order hijacking, periodic HTTPS beaconing, custom payload parsing, and multiple C2 endpoints, including fallback infrastructure.
- BridgeHead and ArcBridge are custom WebSocket tunneling tools that provide covert SOCKS5-style access and operator-controlled relay capabilities.
- Both tunneling tools include environment checks and proxy-aware logic, helping them run on selected victim machines and traverse corporate proxy setups.
- Victims were observed across Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, with activity affecting government, SMB, aviation, telecom, and financial sectors.
MITRE Techniques
- [T1566.001] Spearphishing Attachment â Delivered malicious archives through highly targeted recruitment-themed lures and fake videoconferencing pages (âtargeted spear-phishing campaignsâ and âredirected victims to malicious archivesâ).
- [T1195.002] Supply Chain Compromise: Compromise Software Supply Chain â Used third-party file-sharing services and impersonated trusted brands/platforms to distribute payloads (âimpersonating trusted brands and hiring platformsâ).
- [T1574.001] DLL Search Order Hijacking â NightLedger masquerades as SspiCli.dll and is loaded via AppVShNotify.exe search-order behavior (âdesigned for DLL search-order hijackingâ).
- [T1027] Obfuscated Files or Information â NightLedger tokenizes custom C2 payloads and TWOSTROKE uses hex-encoded responses (âtokenizes the payloadâ and âhex-encodedâ).
- [T1071.001] Application Layer Protocol: Web Protocols â NightLedger communicates over HTTPS and returns command output via HTTP POST (âcontacts its C2 over HTTPSâ and âreturned to the C2 via an HTTP POST requestâ).
- [T1105] Ingress Tool Transfer â The implant can download files, upload files, and retrieve malicious archives used in delivery (âDownload a fileâ and âUpload file to C2 serverâ).
- [T1001] Data Obfuscation â Custom delimiters and encoded response parsing conceal command data (âuses the custom delimiter (#%%#)â).
- [T1041] Exfiltration Over C2 Channel â Command output, files, and collected logs are sent back through the C2 channel (âCommand output is returned to the C2â).
- [T1056.001] Input Capture: Keylogging â Not directly present; no evidence in the article of keystroke capture, so omit.
- [T1125] Video Capture â The article states screen capture rather than webcam capture; NightLedger takes screenshots (âTake a screenshotâ).
- [T1113] Screen Capture â NightLedger can capture screenshots from the infected system (âTake a screenshotâ).
- [T1083] File and Directory Discovery â NightLedger lists directories, logical drives, and processes (âList directoriesâ and âEnumerate logical drivesâ).
- [T1057] Process Discovery â NightLedger lists processes and gathers process-list output (âList processesâ).
- [T1059.003] Command and Scripting Interpreter: Windows Command Shell â The implant can execute a process/program, indicating command execution capability (âExecute a process/programâ).
- [T1106] Native API â BridgeHead dynamically loads advapi32.dll and resolves GetUserNameA; proxy handling uses WinHttpQueryAuthSchemes (âdynamically loads advapi32.dllâ and âWinHttpQueryAuthSchemesâ).
- [T1090.002] Proxy: External Proxy â BridgeHead and related tooling traverse corporate proxies and handle HTTP 407 responses (âoperate through corporate proxy environmentsâ).
- [T1090.001] Proxy: Internal Proxy â The WebSocket tunneler functions as a relay node for operator traffic through the victim environment (âall resulting TCP traffic is tunneled through the victimâs machineâ).
- [T1219] Remote Access Software â The tunneling utilities provide persistent operator access and remote relay functionality (âoperator-controlled tunnelingâ).
- [T1005] Data from Local System â NightLedger collects NetSetup.log from the local machine (âCollect C:WindowsdebugNetSetup.logâ).
- [T1047] Windows Management Instrumentation â Not mentioned; omit if not supported by the article.
- [T1036] Masquerading â NightLedger masquerades as a legitimate DLL and BridgeHead uses plausible filenames/paths (âmasquerades as SspiCli.dllâ and âstored as âŚlibwinpthread-1.dllâ).
Indicators of Compromise
- [File hashes] NightLedger, ArcBridge, and BridgeHead samples â A239E655709A2518DD0B7BDBED163679, 5FA15EF96808EA82F0A6176F0BB4B38642F847597109DA2A220391BB09D00676AFB1C1583606599C7272CFB33CC6F498, and 6038D42AF0AFFD1FB263F470C0956F6B
- [File hashes] Additional BridgeHead-related samples â AE628EFA305387B633DCE82F9364875B, F7D36CC5904A53252D2BB3D21615134F, C90F0EFADBF322E5EB1C4103A38C30E6, D09B14A2FE01C7363ECC56F5D046162C, and other 1 item
- [Domains] C2 and infrastructure domains â smartconnect[.]azurewebsites[.]net, businessmixture[.]com, realhealthshop[.]com, and tjconsultingservices[.]com
- [Domains] Additional lure and hosting domains â aecert[.]org, global-reds[.]com, neexportfolio[.]azurewebsites[.]net, and other 15 items
- [IP addresses] Associated infrastructure â 172[.]86[.]98[.]113
- [File names] Malware and staged DLLs â sspicli.dll, unbcl.dll, libwinpthread-1.dll, and IPHLPAPI.dll
- [File paths] Deployment locations and staged paths â %LocalAppData%MicrosoftVisualStudio, C:program files (x86)univpnpromotelibwinpthread-1.dll, and C:WindowsdebugNetSetup.log
- [Mutexes] Single-instance identifiers â A8215357-F99A-44FE-BC65-D8F0434B0C03 and F56E68DA-4A89-46B4-9AC8-7290A7651000
- [URLs / endpoints] C2 and protocol endpoints â /edfcvfgbhnjmkqwasderfgg, /qasxcdfvgbhnmyuioplkhnj, /wsdefvvbnhyuijkplmbgfrtt, and /connect
Read more: https://securelist.com/mirage-kitten-new-tools/120811/