Mirage Kitten, a highly sophisticated and elusive group, has been linked to a new malware campaign targeting the Middle East and Africa regions. Kaspersky researchers identified the malware as NightLedger, a sophisticated backdoor, ArcBridge, a powerful tunneling tool, and BridgeHead, another advanced tunneling tool. The malware campaign is believed to have started in late 2022, with the initial targets being government agencies and organizations in the Middle East and Africa.
The researchers found that the malware campaign was designed to create a secure backdoor into the targeted systems, allowing Mirage Kitten to maintain access and exfiltrate sensitive information. The group's use of advanced tunneling tools, such as ArcBridge and BridgeHead, enabled them to bypass traditional security measures and evade detection.
According to Kaspersky, the malware campaign was carried out using a combination of phishing and social engineering tactics to trick victims into installing the malware. The researchers note that the malware was highly sophisticated and designed to evade detection by traditional security software.
The discovery of the Mirage Kitten malware campaign highlights the ongoing threat posed by sophisticated groups like Mirage Kitten, which continue to evolve and adapt their tactics to evade detection.