{"id":1832,"date":"2026-08-02T07:23:37","date_gmt":"2026-08-02T00:23:37","guid":{"rendered":"https:\/\/vncybers.vn\/ho-so-mirage-kitten-nightledger-chien-thuat-bam-sau-vao-mang-muc-tieu\/"},"modified":"2026-08-02T07:23:37","modified_gmt":"2026-08-02T00:23:37","slug":"mirage-kitten-nightledger-target-network-persistence-profile","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/ho-so-mirage-kitten-nightledger-chien-thuat-bam-sau-vao-mang-muc-tieu\/","title":{"rendered":"Mirage Kitten profile: NightLedger and its tactics to stick deep into target networks"},"content":{"rendered":"<p>Mirage Kitten, also known as UNC1549, Smoke Sandstorm or Nimbus Manticore, continues to show the maturity of an APT group specializing in cyber espionage in the Middle East and Africa. Kaspersky's new report said that this group used a set of tools that have never been publicly announced, including the NightLedger backdoor and two WebSocket tunneling tools, ArcBridge and BridgeHead.<\/p>\n<p>The notable point is not just the new code name. This tool chain reflects how modern cyber espionage groups move from initial gain to maintaining long-term access, hiding within the corporate infrastructure and turning the victim machine into a transit point for deeper exploration of the internal network.<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/mirage-kitten-inline.jpg\" alt=\"Ph\u00f2ng m\u00e1y ch\u1ee7 minh h\u1ecda cho ho\u1ea1t \u0111\u1ed9ng gi\u00e1m s\u00e1t v\u00e0 \u0111i\u1ec1u tra chi\u1ebfn d\u1ecbch Mirage Kitten\" style=\"width:100%; height:auto;\" \/><figcaption>Illustration: server infrastructure and network monitoring in a corporate environment.<\/figcaption><\/figure>\n<h2>Who is Mirage Kitten?<\/h2>\n<p>According to Kaspersky, Mirage Kitten is an APT group that focuses on cyber espionage campaigns targeting the fields of aviation, defense, telecommunications and government organizations in the Middle East, Africa and some related regions. This group has been tracked by other security firms under many names, including UNC1549, Smoke Sandstorm and Nimbus Manticore.<\/p>\n<p>The common denominator in Mirage Kitten's operations is selecting targets with high intelligence value, using personalized decoys, and deploying malware in multiple layers. Documented lures include fake recruitment content, online meeting portals that look like legitimate services, and compressed files saved on third-party sharing platforms.<\/p>\n<h2>NightLedger: new backdoor for the persistence phase<\/h2>\n<p>NightLedger is a new Windows backdoor that Kaspersky attributed to Mirage Kitten based on code and behavioral similarities with the group's historical implants. Reader code in file format <strong>SspiCli.dll<\/strong> and leverage DLL search-order hijacking techniques to be loaded with a legitimate process.<\/p>\n<p>Once run, NightLedger creates a mutex to ensure that only one instance is active on the victim machine. The malware communicates with the control server over HTTPS, receives commands using a custom parsed format, and sends the results back to the C2 infrastructure. The supported commands show a clear goal: collect user and server information, list directories, download files, run processes, take screenshots, list drives, list processes, and get some Windows diagnostic logs.<\/p>\n<p>Operationally, NightLedger is not an instant destructive tool. It serves as a flexible anchor point for attackers to understand the environment, choose their next move, and maintain access without generating too many unusual signals.<\/p>\n<h2>ArcBridge and BridgeHead: turn the victim's machine into a tunnel<\/h2>\n<p>Two tools ArcBridge and BridgeHead show that Mirage Kitten focuses on the ability to move within the internal network after intrusion. BridgeHead was discovered by Kaspersky during post-exploitation operations in Egypt and an aviation and aerospace organization in Pakistan. This tool establishes WebSocket connections over HTTPS, handles enterprise proxy environments, and can act as a SOCKS5 tunnel proxy.<\/p>\n<p>In other words, the infected machine can become a relay point for the operator to run tools from the control server side, but the traffic passes through the victim's network. This makes scanning, accessing internal services, or connecting to sensitive resources difficult to distinguish from legitimate traffic within the enterprise.<\/p>\n<p>BridgeHead also has signs that are adjusted for each target. A variant that only fires if the Windows username contains a specific string of characters. This is a technique that helps malware avoid running in an automated analysis environment and shows that the attacker has reconnaissance information before deploying.<\/p>\n<h2>Victims and strategic significance<\/h2>\n<p>Kaspersky said its telemetry recorded victims in Egypt, Jordan, Tanzania, Pakistan, Ethiopia and Burkina Faso, ranging from government environments, small and medium enterprises, aviation, telecommunications to finance. This target range is suitable for a cyber espionage campaign whose goal is to gather long-term information rather than make a quick buck.<\/p>\n<p>The emergence of NightLedger, ArcBridge and BridgeHead also shows that APT groups are increasingly investing in specialized tools for real enterprise environments: with proxies, with access control, with EDR monitoring and with multiple internal network layers. Instead of relying on just a single backdoor, the toolkit is clearly divided between information gathering, command execution, and tunneling.<\/p>\n<h2>Defensive Lessons<\/h2>\n<p>For high-risk organizations, defending against Mirage Kitten cannot stop at just blocking malicious code by hash. Watch for unusual DLL sideloading behavior, outbound WebSocket connections from unfamiliar processes, changes in user directories, recurring C2 queries, and signs of a workstation suddenly becoming an internal traffic transit point.<\/p>\n<p>Security teams should also carefully check for legitimate executables that include unfamiliar DLLs, especially in user directories or rarely monitored application directories. In environments with enterprise proxies, logging detailed WebSocket sessions and comparing them to a list of valid applications can help detect tunneling tools before attackers extend access.<\/p>\n<p>Mirage Kitten is a typical example of the trend of silent attacks: making little noise, choosing targets carefully, using their own tools and prioritizing long-term attachment rather than immediate impact. The important lesson is to look at cybersecurity as a continuous process of behavioral detection, not just a race to patch individual indicators.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from Kaspersky Securelist<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Mirage Kitten, c\u00f2n \u0111\u01b0\u1ee3c bi\u1ebft \u0111\u1ebfn v\u1edbi c\u00e1c t\u00ean UNC1549, Smoke Sandstorm ho\u1eb7c Nimbus Manticore, ti\u1ebfp t\u1ee5c cho th\u1ea5y m\u1ee9c \u0111\u1ed9 tr\u01b0\u1edfng th\u00e0nh c\u1ee7a m\u1ed9t nh\u00f3m APT chuy\u00ean ho\u1ea1t \u0111\u1ed9ng gi\u00e1n \u0111i\u1ec7p m\u1ea1ng t\u1ea1i Trung \u0110\u00f4ng v\u00e0 ch\u00e2u Phi. B\u00e1o c\u00e1o m\u1edbi c\u1ee7a Kaspersky cho bi\u1ebft nh\u00f3m n\u00e0y \u0111\u00e3 s\u1eed d\u1ee5ng m\u1ed9t b\u1ed9 c\u00f4ng c\u1ee5 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1830,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[70],"tags":[118,537,538,541,530,413,539,532,536,535,534,533,540],"class_list":["post-1832","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ho-so","tag-apt","tag-arcbridge","tag-bridgehead","tag-cyber-espionage","tag-dll-side-loading","tag-ho-so-an-ninh-mang","tag-kaspersky-securelist","tag-mirage-kitten","tag-nightledger","tag-nimbus-manticore","tag-smoke-sandstorm","tag-unc1549","tag-websocket-tunneling"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1832"}],"version-history":[{"count":0,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1832\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1830"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}