Mirage Kitten targets Middle East and Africa region with new malware
AI Summary
Mirage Kitten, an APT group also known as UNC1549, is conducting cyber-espionage operations targeting aerospace, defense, telecommunications, and government sectors in the Middle East and Africa. The group uses spear-phishing and fake recruitment portals to deploy new malware tools, including NightLedger, a Windows backdoor that performs reconnaissance, command execution, and data exfiltration, and two WebSocket-based tunneling tools, BridgeHead and ArcBridge, which enable covert C2 communications and SOCKS5 tunneling through compromised hosts. The infrastructure includes domains hosted on Azure and Cloudflare, with targeting logic based on username checks to avoid execution in unintended environments.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 35 extracted
| Type | Value | Detail |
|---|---|---|
| MD5 | a239e655709a2518dd0b7bdbed163679 | Details → |
| MD5 | 5fa15ef96808ea82f0a6176f0bb4b386 | Details → |
| MD5 | 42f847597109da2a220391bb09d00676 | Details → |
| MD5 | afb1c1583606599c7272cfb33cc6f498 | Details → |
| MD5 | 6038d42af0affd1fb263f470c0956f6b | Details → |
| MD5 | ae628efa305387b633dce82f9364875b | Details → |
| MD5 | f7d36cc5904a53252d2bb3d21615134f | Details → |
| MD5 | c90f0efadbf322e5eb1c4103a38c30e6 | Details → |
| MD5 | d09b14a2fe01c7363ecc56f5d046162c | Details → |
| MD5 | c832ecd135781b11f59e3fffb3d2b6ac | Details → |
| Domain | smartconnect[.]azurewebsites[.]net | Details → |
| Domain | businessmixture[.]com | Details → |
| Domain | global-reds[.]com | Details → |
| Domain | maadinglobal[.]com | Details → |
| Domain | business-deegital[.]com | Details → |
| Domain | business-deegital[.]azurewebsites[.]net | Details → |
| Domain | businessdeegital[.]azurewebsites[.]net | Details → |
| Domain | neexportfolio[.]azurewebsites[.]net | Details → |
| Domain | neexportfolio[.]com | Details → |
| Domain | aecert[.]org | Details → |
| Domain | realhealthshop[.]com | Details → |
| Domain | tjconsultingservices[.]com | Details → |
| Domain | thehealth-life[.]com | Details → |
| Domain | buisness-centeral-transportation[.]com | Details → |
| Domain | healthcarezoom-centeral[.]azurewebsites[.]net | Details → |
| Domain | healthcarezoomcenteral[.]azurewebsites[.]net | Details → |
| Domain | healthcarezoomcenteral[.]org | Details → |
| Domain | toadreport[.]azurewebsites[.]net | Details → |
| Domain | business-startup[.]azurewebsites[.]net | Details → |
| Domain | businessstartup[.]azurewebsites[.]net | Details → |
| IP | 172[.]86[.]98[.]113 | Details → |
| Filename | sspicli.dll | Details → |
| Filename | unbcl.dll | Details → |
| Filename | libwinpthread-1.dll | Details → |
| Filename | IPHLPAPI.dll | Details → |