Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and Africa — Threadlinqs Intelligence
As of 2026-07-28, Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and Africa is a high-severity apt threat attributed to Mirage Kitten (Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1741 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: Mirage Kitten · Iran · ESPIONAGE
Kaspersky Securelist documents three previously undocumented tools used by the Iranian, IRGC-linked Mirage Kitten actor (UNC1549/Smoke Sandstorm/Nimbus Manticore): the NightLedger Windows backdoor,
Mirage Kitten (publicly tracked across the industry as UNC1549, Smoke Sandstorm, Nimbus Manticore, and Subtle Snail) is an Iranian, IRGC-linked espionage actor assessed as a subgroup of the Charming Kitten (APT35 / Eclipsed Wasp) network with ties to Tortoiseshell (Unyielding Wasp). Active since at least June 2022 when Mandiant first documented its MINIBIKE/SlugResin backdoor against aerospace and defense targets, the group has since iterated its toolset (MiniJunk, MiniBrowse, SIGHTGRAB, TRUSTRAP) while consistently relying on spear-phishing delivered through fake, React-based recruitment portals impersonating Boeing, Airbus, Teledyne FLIR, Rheinmetall, and flydubai, luring victims -- often via LinkedIn recruiter personas -- into downloading malicious archives.
In a July 28, 2026 report, Kaspersky's Securelist documented three previously undocumented tools used in the actor's latest campaign against the Middle East, Africa, and Europe. NightLedger is a Windows backdoor loaded through DLL search-order hijacking: the legitimate AppVShNotify.exe does not directly import SspiCli.dll, but RPCRT4.dll delay-loads it during RPC authentication, allowing the actor's malicious SspiCli.dll masquerade to be sideloaded from the process's own directory. NightLedger communicates over HTTPS using a custom #%%# delimiter to the primary C2 realhealthshop[.]com (endpoint /edfcvfgbhnjmkqwasderfgg) with tjconsultingservices[.]com as fallback, and supports host/user enumeration, process execution and termination, directory listing, file upload/download, screenshot capture, drive enumeration, NetSetup.log collection, and DLL loading. Kaspersky notes NightLedger's C2 response-parsing structure mirrors the historical TWOSTROKE backdoor (which uses an @##@ delimiter instead of #%%#), reinforcing attribution to Mirage Kitten's established tradecraft.
BridgeHead and ArcBridge are companion WebSocket-based tunneling tools providing covert C2 and SOCKS5 proxying through corporate proxy infrastructure -- functional successors to the actor's earlier LIGHTRAIL and POLLBLEND tunnelers. BridgeHead (unbcl.dll, libwinpthread-1.dll), dropped under %LocalAppData%\Microsoft\VisualStudio\ and C:\program files (x86)\univpn\promote\, uses an 8-byte-minimum custom binary wire format (message type, connection ID, flags, data length, payload) with CONNECT/CONNECT_RESPONSE/DATA/DISCONNECT/PING/PONG/FLOWCTRL message types, a 30-second keepalive, binary-token authentication with a 10-second timeout, and native handling of HTTP 407 proxy-authentication challenges -- preferring Windows SSO Negotiate over NTLM -- to tunnel out through victim corporate proxies to smartconnect[.]azurewebsites[.]net. It restricts execution to specific victims by checking for a hardcoded substring inside the lowercased Windows username and silently exiting if there is no match. ArcBridge, first identified by Kaspersky in April 2026, communicates with aecert[.]org over port 443 and supports OPEN (tunnel session) and DNS (resolution) commands.
The campaign's spear-phishing continues the actor's recruitment-lure playbook alongside fake videoconferencing pages that redirect victims to malicious file-sharing archives. Targeting spans aerospace, aviation, defense, telecommunications, finance, and government-sector organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso, and the broader Middle East, Africa, and Europe region -- consistent with the actor's prior 2025 expansion into Denmark, Sweden, Portugal, Israel, and the UAE. Kaspersky observes an infrastructure shift away from Microsoft Azure subdomains toward Cloudflare-backed domains, alongside continued use of Azure Websites hosting (smartconnect[.]azurewebsites[.]net, toadreport[.]azurewebsites[.]net). No CVE or scored vulnerability is associated with this campaign; the DLL search-order hijacking technique abuses legitimate Windows RPC library-loading behavior (CWE-427) rather than a specific software flaw. Kaspersky assesses t
Weaknesses (CWE)
CWE-427, CWE-506
Target sectors: aerospace, aviation, defense, telecoms, finance, government administration
Target regions: Middle East, Africa, Europe
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1591, T1598, T1583, T1585, T1608, T1587, T1566, T1204, T1059, T1106