Mirage Kitten Deploys New Malware Suite Against Aerospace and Defense Targets in Egypt, Pakistan
AI-generated from multiple sources. Verify before acting on this reporting.
CAIRO (July 28) — The advanced persistent threat group known as Mirage Kitten has deployed a new suite of malware targeting critical infrastructure organizations across Egypt and Pakistan. Security analysts identified the campaign on Monday, noting that the group is utilizing a newly discovered backdoor named NightLedger alongside two tunneling tools to maintain access within compromised networks.
The cyber-espionage operation specifically focuses on entities operating within the aerospace, aviation, defense, and telecommunications sectors in both nations. Mirage Kitten, also tracked as UNC1549 by cybersecurity researchers, has historically conducted long-term intrusion campaigns against government-linked targets in the Middle East and Africa regions. The latest activity marks a significant evolution in their technical capabilities.
The NightLedger backdoor serves as the primary mechanism for establishing persistent access on victim systems. Once deployed, it allows attackers to execute remote commands and exfiltrate sensitive data without triggering standard security alarms. To facilitate command-and-control communications that bypass network firewalls, Mirage Kitten paired the backdoor with two distinct tunneling tools designed to encapsulate malicious traffic within legitimate-looking protocols.
Organizations in Egypt's aviation sector appear to be a primary target of this specific wave of activity, followed closely by defense contractors and telecommunications firms operating out of Pakistan. The timing of the deployment coincides with heightened geopolitical tensions involving aerospace developments in both countries, though no direct link between the attacks and current diplomatic events has been established.
The group's methodology suggests an intent to gather intelligence on proprietary aircraft designs, satellite communication protocols, and defense procurement strategies. By targeting telecommunications infrastructure, attackers may also be seeking access to broader network backbones that connect military and civilian systems.
Security firms have issued alerts urging organizations in the affected sectors to scan for indicators associated with NightLedger and the accompanying tunneling tools. Remediation efforts require isolating infected endpoints and patching vulnerabilities exploited during the initial intrusion phase. The sophistication of the new malware set indicates a well-resourced operation capable of adapting quickly to defensive measures.
It remains unclear how long Mirage Kitten has been operating within these networks prior to the detection of NightLedger, or whether other sectors beyond aerospace and defense are currently compromised. Investigators continue to monitor for additional variants of the tunneling tools as the group potentially expands its operational scope across the wider Middle East and Africa region.