Mirage Kitten — APT Profile

Mirage Kitten is a cyber espionage group that targets aerospace, aviation, defense and telecommunications organizations, historically across the Middle East and Europe and, as of 2026, increasingly across Africa. It is tracked elsewhere as UNC1549, Smoke Sandstorm and Nimbus Manticore. The group relies on highly tailored social engineering rather than mass phishing, including fake recruitment portals that impersonate trusted employers and hiring platforms, and lookalike videoconferencing pages that redirect targets to malicious archives hosted on legitimate file-sharing services. Its tooling favors quiet, durable access over disruption: custom multi-stage backdoors paired with WebSocket tunnelers that turn a compromised machine into a relay, so operator traffic appears to originate inside the target network. Payloads are frequently tailored to a single host, checking the logged-in Windows username before activating, which both indicates prior internal reconnaissance and keeps samples inert in analysis sandboxes. Kaspersky reporting in July 2026 documented three previously undocumented tools (NightLedger, ArcBridge and BridgeHead) and a gradual shift away from Microsoft Azure subdomain infrastructure toward Cloudflare-backed domains, likely intended to complicate attribution. On attribution: Kaspersky does not name a state sponsor, though the group's other designations sit in the naming families Microsoft ("Sandstorm") and Check Point ("Manticore") use for Iran-linked operations.

Also tracked as

UNC1549, Smoke Sandstorm, Nimbus Manticore

IntelFusions coverage (2)

Tools & malware

Vendor research

Read the full analysis on IntelFusions