Skip to main content

Kaspersky uncovers new Mirage Kitten malware used in cyber-espionage campaign across the Middle East and Africa

July 28, 2026

Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.

The company’s researchers have identified victims of this campaign across the Middle East and Africa, including organizations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, aviation organizations in Pakistan, telecommunications companies in Ethiopia and financial-sector entities in Burkina Faso.

The toolset consists of three custom programs. At its core is NightLedger, a newly discovered Windows backdoor attributed to the group based on code and behavioral similarities to its previously known malware, which gives the attackers remote control over infected machines: they can run commands, explore and transfer files and capture screenshots. It is complemented by two covert tunneling tools, ArcBridge and BridgeHead, which effectively turn a compromised computer into a relay node: the attackers run their tools on their own servers, while all the resulting traffic is quietly funneled through the victim's machine, as if it originated from inside the victim's network. This lets them slip past network defenses and preserve long-term access without drawing attention. The first of these tools was identified in April 2026 in activity targeting victims in the Middle East.

While the initial access vector remains unclear in most cases, Kaspersky GReaT researchers observed BridgeHead being deployed during post-compromise activity in victim environments in Egypt and at an aerospace and aviation organization in Pakistan. In those cases, the intrusion activity followed targeted spear-phishing attempts consistent with the group’s known methods. The lures were highly tailored including recruitment-themed messages impersonating trusted brands and hiring platforms, as well as fake videoconferencing pages that redirected victims to malicious archive files hosted on third-party file-sharing services.

“Based on our latest findings, we conclude that Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations across the Middle East and Africa. Another notable aspect of the campaign is the group's continued reliance on tunneling utilities as part of its operational toolkit: in practice this enables attackers to bypass network controls, maintain covert access to compromised environments and significantly complicate detection efforts. Given the persistence and sophistication of these techniques, organizations and defenders should incorporate these findings into their threat assessments and strengthen their detection and response capabilities accordingly,” says Omar Amin, senior security researcher at Kaspersky GReAT.

More details available on Securelist.com

To stay protected from Mirage Kitten and other APT’s, organizations are advised to follow these best practices: 

  • Remain highly vigilant against the deployment of Mirage Kitten toolset, including NightLedger, ArcBridge and BridgeHead tunneling tools. 

  • To protect the company against a wide range of threats, use solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR for organizations of any size and industry. Depending on your current needs and available resources, you can choose the most relevant product tier and easily migrate to another one if your cybersecurity requirements are changing.

  • Adopt managed security services by Kaspersky such as Compromise Assessment, Managed Detection and Response (MDR) and / or Incident Response, covering the entire incident management cycle – from threat identification to continuous protection and remediation. They help to protect against evasive cyberattacks, investigate incidents and provide additional expertise even if a company lacks cybersecurity workers.

  • Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organization. Kaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.

 

About the Global Research & Analysis Team

Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.

Kaspersky uncovers new Mirage Kitten malware used in cyber-espionage campaign across the Middle East and Africa

Kaspersky Global Research and Analysis Team (GReAT) has discovered a previously undocumented malware set used by Mirage Kitten APT. The tools were used in a targeted campaign aimed at maintaining long-term access to victim networks and stealing sensitive data.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases