KASPERSKY has reported on the Mirage Kitten malware, also known as UNC1549, which targets sectors like aviation, defense, telecom, government, and finance across the Middle East and Africa. This state-aligned espionage group has deployed a new Windows backdoor called NightLedger, alongside two tunneling tools, ArcBridge and BridgeHead. The malware utilizes social engineering tactics, such as recruitment-themed messages, to lure victims.
The group has been linked to Iran's IRGC, and its activities represent a continuation of earlier cyber espionage strategies. Protection measures include employee training to recognize malicious lures, enforcing multi-factor authentication, and monitoring for suspicious activity.