Iranian-linked threat actor Mirage Kitten (APT35/Nimbus Manticore) has launched a sophisticated cyber-espionage campaign targeting strategic entities in the Middle East, Africa, and South Asia. The operation utilizes "NightLedger," a previously undocumented Windows-based backdoor, alongside specialized WebSocket-based tunneling tools, "ArcBridge" and "BridgeHead." These tools facilitate stealthy command-and-control (C2) communications and data exfiltration by masking traffic within the WebSocket protocol, specifically designed to bypass traditional network security monitoring and EDR/AV detection. This evolution marks a significant shift toward protocol-based evasion to maintain long-term persistence within high-value regional networks.
-
Campaign Overview: Regional Espionage Focus
- Targets strategic organizations across the Middle East, Africa, and South Asia.
- Primary objective is state-aligned espionage to gather intelligence on regional geopolitical entities.
- Demonstrates a highly coordinated effort to expand intelligence-gathering capabilities through targeted operations.
-
Attack Mechanics: Advanced Evasion Techniques
- Deployment of "NightLedger," a custom, undocumented Windows backdoor for initial persistence.
- Use of "ArcBridge" and "BridgeHead" as specialized WebSocket-based tunneling mechanisms.
- Leveraging WebSocket protocols to bypass traditional network security monitoring and perimeter inspection.
- Engineered to minimize detection by existing EDR and signature-based AV solutions.
-
Threat Actor Profile: Mirage Kitten (APT35)
- Also documented as Nimbus Manticore, Smoke Sandstorm, and Charming Kitten.
- Linked to Iranian state-sponsored interests and strategic intelligence collection.
- Exhibits increasing technical maturity through the development of non-standard, custom toolsets.
-
Defensive Implications: Detection and Mitigation
- Necessity for enhanced monitoring of WebSocket-based traffic to identify anomalous C2 patterns.
- Traditional signature-based detection may fail against undocumented payloads like NightLedger.
- Urgent need for behavioral-based network traffic analysis (NTA) to detect protocol-level tunneling.
-
Conclusion: Evolving Threat Landscape
- Mirage Kitten's transition to WebSocket tunneling represents a significant advancement in evasion capabilities.
- Organizations in target regions must prioritize advanced telemetry and protocol-aware network inspection.
Related posts
- Securelist (Kaspersky) — Mirage Kitten targets Middle East and Africa region with new malware
- TechNadu — Mirage Kitten’s New Malware Toolkit Targets Aerospace and Defense Across Middle East and Africa
- feeds.feedburner.com — Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
- Mallory
- Kaspersky
- En
- Huntandhackett
- Vectra
- Malpedia
- Arabianbusiness