Mirage Kitten is an Iranian-aligned advanced persistent threat group engaged in cyber-espionage. It is also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. The group has targeted organizations in aerospace, aviation, defense, telecommunications, government, finance, and small-to-medium business sectors, with activity observed across the Middle East, Europe, and parts of Africa. Mirage Kitten is known for highly targeted intrusion operations that rely on tailored spear-phishing and social-engineering lures, including recruitment-themed pretexts and fake videoconferencing pages, to gain initial access. Its post-compromise tradecraft emphasizes persistence, reconnaissance, data theft, and covert operator access into victim environments. The group has used custom Windows malware for command execution, file transfer, screenshot capture, host and process discovery, and collection of system artifacts relevant to victim profiling and lateral activity. A notable element of Mirage Kitten’s toolkit is its use of custom tunneling and proxy malware to relay traffic through compromised systems and provide stealthy access from victim networks. Associated tooling includes the NightLedger backdoor and the BridgeHead and ArcBridge tunneling utilities. NightLedger has been used as a multi-stage Windows backdoor supporting reconnaissance, remote command execution, file operations, screenshot capture, and exfiltration, and has been deployed through DLL search-order hijacking. BridgeHead and ArcBridge use WebSocket-based communications to establish covert tunnels or proxy sessions, enabling operator-controlled network access that can blend with enterprise traffic patterns. BridgeHead has also demonstrated proxy-aware authentication logic and victim-specific execution checks, indicating careful tailoring to intended targets. The group’s malware development shows continuity with earlier Mirage Kitten tooling, including similarities between NightLedger and the previously reported TWOSTROKE backdoor, and an ongoing operational preference for tunneling utilities seen in prior activity involving tools such as LIGHTRAIL and POLLBLEND. Mirage Kitten has also adapted aspects of its command-and-control infrastructure over time, including movement away from some earlier hosting patterns toward infrastructure choices intended to complicate attribution and improve resilience. Overall, Mirage Kitten is a focused espionage actor whose operations are characterized by selective targeting, customized malware, covert tunneling capability, and sustained interest in strategically significant sectors and regional organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting targeted cyber-espionage operations across the Middle East, Europe, and Africa using spear-phishing, fake recruitment portals, custom backdoors, and WebSocket-based tunneling tools for persistence, covert access, and data exfiltration.
Conducting targeted cyber-espionage operations across the Middle East, Europe, and Africa against aerospace, aviation, defense, telecommunications, government, SMB, and financial-sector entities using spear-phishing, fake recruitment portals, lookalike videoconferencing pages, custom backdoors, and WebSocket-based tunneling tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.