# Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) Deploys New NightLedger Backdoor and BridgeHead/ArcBridge WebSocket Tunnelers Against Middle East and Africa

> Kaspersky Securelist documents three previously undocumented tools used by the Iranian, IRGC-linked Mirage Kitten actor (UNC1549/Smoke Sandstorm/Nimbus Manticore): the NightLedger Windows backdoor, loaded via DLL search-order hijacking of AppVShNotify.exe, and the BridgeHead and ArcBridge WebSocket-based tunneling tools used for covert C2 and SOCKS5 proxying through corporate proxies. The campaign uses spear-phishing recruitment lures and fake videoconferencing pages targeting aerospace, aviation, defense, telecommunications, finance, and government sectors across Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso, and the wider Middle East/Africa/Europe region.

- **Published:** 2026-07-28T00:00:00Z
- **Last reviewed:** 2026-07-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1741
- **ID:** TL-2026-1741
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Mirage Kitten (Iran)
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Mirage Kitten (publicly tracked across the industry as UNC1549, Smoke Sandstorm, Nimbus Manticore, and Subtle Snail) is an Iranian, IRGC-linked espionage actor assessed as a subgroup of the Charming Kitten (APT35 / Eclipsed Wasp) network with ties to Tortoiseshell (Unyielding Wasp). Active since at least June 2022 when Mandiant first documented its MINIBIKE/SlugResin backdoor against aerospace and defense targets, the group has since iterated its toolset (MiniJunk, MiniBrowse, SIGHTGRAB, TRUSTRAP) while consistently relying on spear-phishing delivered through fake, React-based recruitment portals impersonating Boeing, Airbus, Teledyne FLIR, Rheinmetall, and flydubai, luring victims -- often via LinkedIn recruiter personas -- into downloading malicious archives.

In a July 28, 2026 report, Kaspersky's Securelist documented three previously undocumented tools used in the actor's latest campaign against the Middle East, Africa, and Europe. NightLedger is a Windows backdoor loaded through DLL search-order hijacking: the legitimate AppVShNotify.exe does not directly import SspiCli.dll, but RPCRT4.dll delay-loads it during RPC authentication, allowing the actor's malicious SspiCli.dll masquerade to be sideloaded from the process's own directory. NightLedger communicates over HTTPS using a custom #%%# delimiter to the primary C2 realhealthshop[.]com (endpoint /edfcvfgbhnjmkqwasderfgg) with tjconsultingservices[.]com as fallback, and supports host/user enumeration, process execution and termination, directory listing, file upload/download, screenshot capture, drive enumeration, NetSetup.log collection, and DLL loading. Kaspersky notes NightLedger's C2 response-parsing structure mirrors the historical TWOSTROKE backdoor (which uses an @##@ delimiter instead of #%%#), reinforcing attribution to Mirage Kitten's established tradecraft.

BridgeHead and ArcBridge are companion WebSocket-based tunneling tools providing covert C2 and SOCKS5 proxying through corporate proxy infrastructure -- functional successors to the actor's earlier LIGHTRAIL and POLLBLEND tunnelers. BridgeHead (unbcl.dll, libwinpthread-1.dll), dropped under %LocalAppData%\Microsoft\VisualStudio\ and C:\program files (x86)\univpn\promote\, uses an 8-byte-minimum custom binary wire format (message type, connection ID, flags, data length, payload) with CONNECT/CONNECT_RESPONSE/DATA/DISCONNECT/PING/PONG/FLOWCTRL message types, a 30-second keepalive, binary-token authentication with a 10-second timeout, and native handling of HTTP 407 proxy-authentication challenges -- preferring Windows SSO Negotiate over NTLM -- to tunnel out through victim corporate proxies to smartconnect[.]azurewebsites[.]net. It restricts execution to specific victims by checking for a hardcoded substring inside the lowercased Windows username and silently exiting if there is no match. ArcBridge, first identified by Kaspersky in April 2026, communicates with aecert[.]org over port 443 and supports OPEN (tunnel session) and DNS (resolution) commands.

The campaign's spear-phishing continues the actor's recruitment-lure playbook alongside fake videoconferencing pages that redirect victims to malicious file-sharing archives. Targeting spans aerospace, aviation, defense, telecommunications, finance, and government-sector organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso, and the broader Middle East, Africa, and Europe region -- consistent with the actor's prior 2025 expansion into Denmark, Sweden, Portugal, Israel, and the UAE. Kaspersky observes an infrastructure shift away from Microsoft Azure subdomains toward Cloudflare-backed domains, alongside continued use of Azure Websites hosting (smartconnect[.]azurewebsites[.]net, toadreport[.]azurewebsites[.]net). No CVE or scored vulnerability is associated with this campaign; the DLL search-order hijacking technique abuses legitimate Windows RPC library-loading behavior (CWE-427) rather than a specific software flaw. Kaspersky assesses the campaign as active and ongoing, with an expanded IOC set available through its Threat Intelligence Reporting service.

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1598 Phishing for Information
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1608 Stage Capabilities
- T1587 Develop Capabilities
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1106 Native API
- T1574 Hijack Execution Flow
- T1053 Scheduled Task/Job
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1083 File and Directory Discovery
- T1057 Process Discovery
- T1087 Account Discovery
- T1120 Peripheral Device Discovery
- T1021 Remote Services
- T1113 Screen Capture
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1572 Protocol Tunneling
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1102 Web Service
- T1041 Exfiltration Over C2 Channel

## Sources

- [Mirage Kitten deploys new tools](https://securelist.com/mirage-kitten-new-tools/120811/)
- [UNC1549 TTPs: Iranian APT Targeting Aerospace and Defense](https://www.picussecurity.com/resource/blog/unc1549-ttps-iranian-apt-targeting-aerospace-and-defense)
- [Iranian Threat Actor Nimbus Manticore Expands Campaigns into Europe with Advanced Malware and Fake Job Lures](https://blog.checkpoint.com/research/iranian-threat-actor-nimbus-manticore-expands-campaigns-into-europe-with-advanced-malware-and-fake-job-lures/)
- [Mandiant tracks surge in UNC1549 campaigns, hitting aerospace and defense through third-party access](https://industrialcyber.co/ransomware/mandiant-tracks-surge-in-unc1549-campaigns-hitting-aerospace-and-defense-through-third-party-access/)
- [Iranian APT Targets Aviation, Software Companies With Updated Tools](https://www.securityweek.com/iranian-apt-targets-aviation-software-companies-with-updated-tools/amp/)
- [Iranian Hackers Use Fake Job Lures to Breach Europe's Critical Industries](https://hackread.com/iranian-hackers-fake-job-breach-europe-industries/)
- [IRGC-linked Nimbus Manticore group attacks defense, aerospace, telecom sectors using Minifast malware toolkit](https://industrialcyber.co/ransomware/irgc-linked-nimbus-manticore-group-attacks-defense-aerospace-telecom-sectors-using-minifast-malware-toolkit/)
- [Check Point tracks Nimbus Manticore Iranian APT targeting critical infrastructure in Europe, Middle East](https://industrialcyber.co/threats-attacks/check-point-tracks-nimbus-manticore-iranian-apt-targeting-critical-infrastructure-in-europe-middle-east/)
- [Nimbus Manticore's Evolving Cyberespionage Campaign](https://blog.polyswarm.io/nimbus-manticores-evolving-cyberespionage-campaign)
- [Nimbus Manticore: Iran's AI-Assisted Backdoors Target Western Sectors](https://labs.cloudsecurityalliance.org/research/csa-research-note-nimbus-manticore-ai-assisted-malware-irgc/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1741
