← Back to Daily Briefing

Iranian-linked threat actor Mirage Kitten (APT35/Nimbus Manticore) has launched a sophisticated cyber-espionage campaign targeting strategic entities in the Middle East, Africa, and South Asia. The operation utilizes "NightLedger," a previously undocumented Windows-based backdoor, alongside specialized WebSocket-based tunneling tools, "ArcBridge" and "BridgeHead." These tools facilitate stealthy command-and-control (C2) communications and data exfiltration by masking traffic within the WebSocket protocol, specifically designed to bypass traditional network security monitoring and EDR/AV detection. This evolution marks a significant shift toward protocol-based evasion to maintain long-term persistence within high-value regional networks.

  • Campaign Overview: Regional Espionage Focus

    • Targets strategic organizations across the Middle East, Africa, and South Asia.
    • Primary objective is state-aligned espionage to gather intelligence on regional geopolitical entities.
    • Demonstrates a highly coordinated effort to expand intelligence-gathering capabilities through targeted operations.
  • Attack Mechanics: Advanced Evasion Techniques

    • Deployment of "NightLedger," a custom, undocumented Windows backdoor for initial persistence.
    • Use of "ArcBridge" and "BridgeHead" as specialized WebSocket-based tunneling mechanisms.
    • Leveraging WebSocket protocols to bypass traditional network security monitoring and perimeter inspection.
    • Engineered to minimize detection by existing EDR and signature-based AV solutions.
  • Threat Actor Profile: Mirage Kitten (APT35)

    • Also documented as Nimbus Manticore, Smoke Sandstorm, and Charming Kitten.
    • Linked to Iranian state-sponsored interests and strategic intelligence collection.
    • Exhibits increasing technical maturity through the development of non-standard, custom toolsets.
  • Defensive Implications: Detection and Mitigation

    • Necessity for enhanced monitoring of WebSocket-based traffic to identify anomalous C2 patterns.
    • Traditional signature-based detection may fail against undocumented payloads like NightLedger.
    • Urgent need for behavioral-based network traffic analysis (NTA) to detect protocol-level tunneling.
  • Conclusion: Evolving Threat Landscape

    • Mirage Kitten's transition to WebSocket tunneling represents a significant advancement in evasion capabilities.
    • Organizations in target regions must prioritize advanced telemetry and protocol-aware network inspection.

Related posts

  1. Securelist (Kaspersky) — Mirage Kitten targets Middle East and Africa region with new malware
  2. TechNadu — Mirage Kitten’s New Malware Toolkit Targets Aerospace and Defense Across Middle East and Africa
  3. feeds.feedburner.com — Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
  4. Mallory
  5. Kaspersky
  6. En
  7. Huntandhackett
  8. Vectra
  9. Malpedia
  10. Arabianbusiness

LINK COPIED TO CLIPBOARD