Threat reportAPTTL-2026-1741

Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and Africa

highACTIVE

Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) (TL-2026-1741) is a high-severity advanced persistent threat campaign, first published 2026-07-28. It is attributed to Mirage Kitten (Iran) with high confidence, affects Microsoft Windows (AppVShNotify.exe / Microsoft Application, maps to 33 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
33MITRE ATT&CK
Actors
1Mirage Kitten
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-1741

Threat ID
TL-2026-1741
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
Mirage Kitten
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
aerospace, aviation, defense, telecoms, finance, government administration
Target regions
Middle East, Africa, Europe
Detection rules
9
Indicators of compromise
30

Malware and tooling in Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore)

Malware and tooling: ArcBridge, BridgeHead, NightLedger

How Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) works

Kaspersky Securelist documents three previously undocumented tools used by the Iranian, IRGC-linked Mirage Kitten actor (UNC1549/Smoke Sandstorm/Nimbus Manticore): the NightLedger Windows backdoor, loaded via DLL search-order hijacking of AppVShNotify.exe, and the BridgeHead and ArcBridge WebSocket-based tunneling tools used for covert C2 and SOCKS5 proxying through corporate proxies. The campaign uses spear-phishing recruitment lures and fake videoconferencing pages targeting aerospace, aviation, defense, telecommunications, finance, and government sectors across Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso, and the wider Middle East/Africa/Europe region.

Mirage Kitten (publicly tracked across the industry as UNC1549, Smoke Sandstorm, Nimbus Manticore, and Subtle Snail) is an Iranian, IRGC-linked espionage actor assessed as a subgroup of the Charming Kitten (APT35 / Eclipsed Wasp) network with ties to Tortoiseshell (Unyielding Wasp). Active since at least June 2022 when Mandiant first documented its MINIBIKE/SlugResin backdoor against aerospace and defense targets, the group has since iterated its toolset (MiniJunk, MiniBrowse, SIGHTGRAB, TRUSTRAP) while consistently relying on spear-phishing delivered through fake, React-based recruitment portals impersonating Boeing, Airbus, Teledyne FLIR, Rheinmetall, and flydubai, luring victims -- often via LinkedIn recruiter personas -- into downloading malicious archives.

In a July 28, 2026 report, Kaspersky's Securelist documented three previously undocumented tools used in the actor's latest campaign against the Middle East, Africa, and Europe. NightLedger is a Windows backdoor loaded through DLL search-order hijacking: the legitimate AppVShNotify.exe does not directly import SspiCli.dll, but RPCRT4.dll delay-loads it during RPC authentication, allowing the actor's malicious SspiCli.dll masquerade to be sideloaded from the process's own directory. NightLedger communicates over HTTPS using a custom #%%# delimiter to the primary C2 realhealthshop[.]com (endpoint /edfcvfgbhnjmkqwasderfgg) with tjconsultingservices[.]com as fallback, and supports host/user enumeration, process execution and termination, directory listing, file upload/download, screenshot capture, drive enumeration, NetSetup.log collection, and DLL loading. Kaspersky notes NightLedger's C2 response-parsing structure mirrors the historical TWOSTROKE backdoor (which uses an @##@ delimiter instead of #%%#), reinforcing attribution to Mirage Kitten's established tradecraft.

BridgeHead and ArcBridge are companion WebSocket-based tunneling tools providing covert C2 and SOCKS5 proxying through corporate proxy infrastructure -- functional successors to the actor's earlier LIGHTRAIL and POLLBLEND tunnelers. BridgeHead (unbcl.dll, libwinpthread-1.dll), dropped under %LocalAppData%\Microsoft\VisualStudio\ and C:\program files (x86)\univpn\promote\, uses an 8-byte-minimum custom binary wire format (message type, connection ID, flags, data length, payload) with CONNECT/CONNECT_RESPONSE/DATA/DISCONNECT/PING/PONG/FLOWCTRL message types, a 30-second keepalive, binary-token authentication with a 10-second timeout, and native handling of HTTP 407 proxy-authentication challenges -- preferring Windows SSO Negotiate over NTLM -- to tunnel out through victim corporate proxies to smartconnect[.]azurewebsites[.]net. It restricts execution to specific victims by checking for a hardcoded substring inside the lowercased Windows username and silently exiting if there is no match. ArcBridge, first identified by Kaspersky in April 2026, communicates with aecert[.]org over port 443 and supports OPEN (tunnel session) and DNS (resolution) commands.

The campaign's spear-phishing continues the actor's recruitment-lure playbook alongside fake videoconferencing pages that redirect victims to malicious file-sharing archives. Targeting spans aerospace, aviation, defense, telecommunications, finance, and government-sector organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso, and the broader Middle East, Africa, and Europe region -- consistent with the actor's prior 2025 expansion into Denmark, Sweden, Portugal, Israel, and the UAE. Kaspersky observes an infrastructure shift away from Microsoft Azure subdomains toward Cloudflare-backed domains, alongside continued use of Azure Websites hosting (smartconnect[.]azurewebsites[.]net, toadreport[.]azurewebsites[.]net). No CVE or scored vulnerability is associated with this campaign; the DLL search-order hijacking technique abuses legitimate Windows RPC library-loading behavior (CWE-427) rather than a specific software flaw. Kaspersky assesses the campaign as active and ongoing, with an expanded IOC set available through its Threat Intelligence Reporting service.

MITRE ATT&CK techniques used in TL-2026-1741

Credential Access

T1003 OS Credential Dumping; T1555 Credentials from Password Stores

Collection

T1005 Data from Local System; T1113 Screen Capture

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1574 Hijack Execution Flow

Discovery

T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery; T1120 Peripheral Device Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Initial Access

T1566 Phishing

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1591 Gather Victim Org Information; T1598 Phishing for Information

Affected products and versions in Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore)

  • Microsoft — Windows (AppVShNotify.exe / Microsoft Application Virtualization client component)
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2016; Windows Server 2019; Windows Server 2022

Remediation for Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore)

Immediate actions

  • Block network communications to realhealthshop[.]com, tjconsultingservices[.]com, smartconnect[.]azurewebsites[.]net, aecert[.]org, businessmixture[.]com, global-reds[.]com, maadinglobal[.]com, healthcarezoomcenteral[.]org, neexportfolio[.]com, toadreport[.]azurewebsites[.]net, and 172.86.98.113 at perimeter firewalls and DNS resolvers.
  • Hunt for the mutexes A8215357-F99A-44FE-BC65-D8F0434B0C03 (NightLedger) and F56E68DA-4A89-46B4-9AC8-7290A7651000 (ArcBridge) across endpoints via EDR.
  • Search for unexpected SspiCli.dll copies alongside AppVShNotify.exe outside %SystemRoot%\System32, and for unbcl.dll / libwinpthread-1.dll under %LocalAppData%\Microsoft\VisualStudio\ or C:\program files (x86)\univpn\promote\.
  • Isolate and forensically image any host exhibiting outbound WebSocket/HTTPS traffic to Azure Websites or Cloudflare-fronted domains carrying the #%%# delimiter or the 8-byte custom binary framing described in this report.

Workarounds

  • Enforce Safe DLL Search Mode and set the CWDIllegalInDllSearch registry policy to reduce DLL search-order hijacking exposure.
  • Block or tightly control third-party VPN/proxy client installation directories (e.g., univpn) to reduce sideloading opportunities for tunneling implants.

Longer-term hardening

  • Deploy application allow-listing / code-signing enforcement to block unsigned DLLs from loading into signed Microsoft binaries such as AppVShNotify.exe.
  • Implement EDR detections for anomalous DLL loads from non-standard directories (DLL search-order hijacking) and for RPCRT4.dll-triggered delay-loads of SspiCli.dll from unexpected paths.
  • Restrict and monitor outbound corporate-proxy authentication (NTLM/Negotiate) to detect SOCKS5 tunneling and proxy-aware C2 abusing HTTP 407 challenge/response flows.
  • Provide targeted phishing-awareness training for HR/recruitment-adjacent staff on fake career-portal and videoconferencing-lure tactics used by Mirage Kitten/UNC1549.

Weaknesses (CWE) in Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore)

CWE-427, CWE-506

Timeline of Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore)

  • UNC1549 (this actor's Mandiant-tracked identity) is first publicly reported deploying the MINIBIKE/SlugResin backdoor against aerospace and defense-sector targets via spear-phishing, establishing the actor's long-running espionage tradecraft.
  • Check Point documents the actor (tracked as Nimbus Manticore) expanding fake-job-lure campaigns into Western Europe (Denmark, Sweden, Portugal) and the Middle East (Israel, UAE) using the MiniJunk backdoor and MiniBrowse credential stealer alongside impersonated Boeing, Airbus, Rheinmetall, and flydubai recruitment portals.
  • Kaspersky researchers first identify the ArcBridge WebSocket tunneler (mutex F56E68DA-4A89-46B4-9AC8-7290A7651000, C2 aecert[.]org:443) in Mirage Kitten intrusion sets.
  • Kaspersky notes Mirage Kitten's C2 hosting pattern shifting from Microsoft Azure subdomains (azurewebsites.net) toward Cloudflare-backed domains, reflected in the mixed use of businessmixture[.]com, global-reds[.]com, and related infrastructure.
  • BridgeHead WebSocket tunneler (unbcl.dll / libwinpthread-1.dll) observed providing SOCKS5 proxying through corporate proxies to smartconnect[.]azurewebsites[.]net, including HTTP 407 proxy-authentication negotiation and Windows SSO abuse.
  • NightLedger backdoor observed deployed via DLL search-order hijacking of AppVShNotify.exe, masquerading as SspiCli.dll and beaconing to realhealthshop[.]com with fallback tjconsultingservices[.]com.
  • Kaspersky assesses the campaign as active and ongoing, with sustained targeting of aerospace, aviation, defense, telecommunications, finance, and government-sector organizations across the Middle East, Africa, and Europe.
  • TL-Intel Harness ingests the Securelist report via RSS and opens threat TL-2026-1741 for tracking and downstream detection engineering.
  • Kaspersky Securelist publishes "Mirage Kitten deploys new tools," formally documenting NightLedger, BridgeHead, and ArcBridge alongside spear-phishing recruitment lures and fake videoconferencing pages targeting Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso.

Sources cited for Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore)

Detection coverage for TL-2026-1741

As of 2026-07-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1741 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats