securelist.com 7/28/2026, 8:31:30 AM · external

Mirage Kitten APT Deploys NightLedger on Aerospace & Telecom

Mirage Kitten APT Deploys NightLedger on Aerospace & Telecom
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

THE article discusses the Mirage Kitten APT group, detailing its focus on cyber-espionage in sectors like aerospace and telecommunications, particularly in the Middle East and Europe. It highlights newly identified malware tools, including the NightLedger backdoor, which enables reconnaissance and command execution, and two WebSocket tunneling tools, ArcBridge and BridgeHead, which facilitate covert network access.

The article also outlines the technical functionalities of these tools, their deployment through spear-phishing, and the group's evolving tactics to maintain a resilient command-and-control infrastructure. It concludes with a summary of the cybersecurity implications and victimology associated with these attacks.

View full article

Article by CyberSIXT