Iranian state-sponsored threat actors have deployed a previously undocumented Windows backdoor dubbed NightLedger across a sprawling campaign targeting government agencies, aviation firms, telecom providers, and financial institutions in the Middle East, Africa, and South Asia, according to research released by Kaspersky’s Global Research and Analysis Team
The activity is attributed to Mirage Kitten, a persistent espionage group also tracked under the aliases Nimbus Manticore, Smoke Sandstorm, and UNC1549
Kaspersky’s telemetry shows confirmed victims across Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso — consistent with the group’s established focus on strategic intelligence gathering in those regions
NightLedger arrives on target machines through a technique that exploits Windows DLL search-order behavior
A legitimate binary, AppVShNotify.exe, indirectly loads a malicious SspiCli.dll placed in the same directory, because AppVShNotify.exe imports RPCRT4.dll, which can delay-load SspiCli.dll during authentication routines
Once executed, the backdoor beacons to a command server over HTTPS and interprets responses split by a custom delimiter — an approach that mirrors the command-parsing design of an earlier Mirage Kitten tool called TWOSTROKE
Its capabilities span reconnaissance, process and file management, screenshot capture, directory listing, DLL injection, and data exfiltration via HTTP POST requests
Alongside the backdoor, Kaspersky identified two WebSocket tunneling tools that turn infected systems into covert relay nodes
BridgeHead operates as a SOCKS5 proxy, routing operator-initiated TCP connections through compromised machines so malicious traffic appears to originate from the victim’s own network
It was observed in Egypt and at an aerospace organization in Pakistan
A second tool, ArcBridge, first spotted in April 2026, provides comparable relay functionality and was deployed against targets in the Middle East
While the specific initial infection vector remains unconfirmed, Mirage Kitten has historically gained entry through targeted phishing campaigns — typically job-offer lures impersonating well-known companies and links to fraudulent videoconferencing platforms
The disclosure follows.
