Retrograde, also known as MiniFast, is a native backdoor associated with the Iran-linked Mirage Kitten threat group, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It uses a distinctive command-and-control registration protocol in which an HTTP 400 response is treated as successful and a session identifier is extracted from the response body. Its command-and-control flow, endpoint structure, beacon timing, command patterns, and enterprise proxy-authentication handling overlap with the later PollCat remote-access trojan. These technical similarities have been used to support attribution of related Mirage Kitten activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers compared PollCat’s network code with an older backdoor called Retrograde, also known as MiniFast, and found that the two use almost the same connection process.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older backdoor whose network-registration logic closely resembles PollCat's, including treating an HTTP 400 response as successful registration and extracting a session token from it.
A native DLL backdoor associated with Mirage Kitten. Its C2 handshake, socketId-based session establishment, host-registration structure, command polling, beacon timing, command identifiers, and proxy-authentication approach are cited as structurally similar to PollCat and NodeRabbit activity.
Native backdoor referenced as a structurally similar Mirage Kitten tool. Its C2 handshake behavior, beacon timing, endpoints, command set, and NTLM proxy delegation behavior were used as attribution evidence for the NodeRabbit and PollCat campaign.
A previously tracked implant/tooling cluster attributed to the same APT, referenced because BridgeHead shares similar proxy traversal and authentication logic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.