Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware dynamically loads advapi32.dll, resolves GetUserNameA ... Notably ... another variant ... shares the same dynamic-resolve stub pattern.
5 PING Bidirectional Keepalive probe, sent every 30 seconds by timer 6 PONG Bidirectional Keepalive reply 9 FLOWCTRL Bidirectional Throttle data flow to prevent buffer overrun
retrieves the current Windows username, converts it to lowercase, and searches for a specific substring in it ... If the substring is not found, the function returns silently without activating ... potentially intended to prevent execution of the standalone malware sample inside virtual analysis systems.
retrieves the current Windows username, converts it to lowercase, and searches for a specific substring in it ... If the substring is not found, the function returns silently without activating ... potentially intended to prevent execution of the standalone malware sample inside virtual analysis systems.
NightLedger periodically contacts its C2 over HTTPS ... establishes an HTTPS WebSocket connection ... communicates with businessmixture.com/blog over WSS on port 443
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom WebSocket-based tunneling implant attributed to Mirage Kitten that establishes authenticated WSS connections, handles enterprise proxy authentication including Negotiate and NTLM, and functions as a full SOCKS5 relay so operators can tunnel traffic through victim hosts.
A custom WebSocket-based SOCKS5 tunnel proxy used in post-exploitation by Mirage Kitten. It performs username-based execution gating, establishes authenticated HTTPS WebSocket connections, handles enterprise proxy authentication including Negotiate and NTLM, and relays operator-directed traffic through victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.