securityonline.info 8/1/2026, 2:11:58 AM · external

Iran linked Mirage Kitten rolls out NightLedger backdoor in MEA

Iran linked Mirage Kitten rolls out NightLedger backdoor in MEA
CyberSIXT Evidence Panel
Primary Source securelist.com
Threat Actor

KASPERSKY has reported on the Mirage Kitten malware, also known as UNC1549, which targets sectors like aviation, defense, telecom, government, and finance across the Middle East and Africa. This state-aligned espionage group has deployed a new Windows backdoor called NightLedger, alongside two tunneling tools, ArcBridge and BridgeHead. The malware utilizes social engineering tactics, such as recruitment-themed messages, to lure victims.

The group has been linked to Iran's IRGC, and its activities represent a continuation of earlier cyber espionage strategies. Protection measures include employee training to recognize malicious lures, enforcing multi-factor authentication, and monitoring for suspicious activity.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline