Mirage Kitten has expanded its malware arsenal with NightLedger, a Windows backdoor abusing DLL search-order hijacking via a malicious SspiCli.dll, and two WebSocket-based tunneling tools (ArcBridge and BridgeHead) that establish SOCKS5 proxy relays through victim networks. The tools employ anti-analysis techniques such as username-substring checks, enterprise proxy traversal with NTLM/Negotiate authentication, and a shift from Azure-hosted to Cloudflare-backed C2 infrastructure to complicate attribution.
UNC1549
1 post
Mirage Kitten targets Middle East and Africa region with new malware