← Back to Tech & Science

Iran-linked cyber group targets aviation and fintech sectors in Africa and Middle East

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

CAIRO (AP) — An Iranian state-backed cyberespionage group known by aliases including Mirage Kitten, UNC1549, Smoke Sandstorm, and Nimbus Manticore has launched a targeted campaign against developers in the aviation, aerospace, and financial technology sectors across Egypt, Ethiopia, and Afghanistan. The operation, detected on Sept. 1, 2026, utilized deceptive job recruitment offers to deliver new malware onto victim systems.

The campaign specifically focused on professionals working within sensitive industries critical to national infrastructure and economic stability in the three nations. Attackers posed as legitimate recruiters, sending unsolicited employment proposals to engineers and software developers. Once recipients engaged with the communications, malicious code was installed on their devices, granting the group unauthorized access to internal networks and proprietary data.

Security researchers identified the intrusion as part of a broader pattern of cyberespionage activity attributed to Iranian actors seeking intelligence on strategic sectors in Africa and the Middle East. The malware deployed in this wave appears designed to exfiltrate technical schematics, source code, and financial algorithms while maintaining a low profile to avoid immediate detection by standard security measures.

The targeted organizations span state-owned enterprises and private developers involved in aircraft maintenance, satellite communications, and digital payment systems. In Egypt, the campaign reached entities linked to the country's expanding aerospace logistics hub. In Ethiopia, targets included firms supporting the nation's growing fintech ecosystem. Afghan developers working on international aviation projects were also identified as recipients of the fraudulent job offers.

No immediate financial losses or public service disruptions have been reported in connection with the attacks. However, security experts warn that the compromise of developer workstations could allow attackers to inject malicious code into future software updates or access sensitive design documents for aircraft and defense systems.

The group behind the attack has a history of targeting government agencies and critical infrastructure globally. Previous operations by Mirage Kitten have involved similar social engineering tactics, leveraging professional networking platforms and email spoofing to gain initial footholds in target networks. The use of multiple aliases suggests the group may be operating under different operational cells or adapting its tradecraft to evade attribution.

Authorities in Egypt, Ethiopia, and Afghanistan have not publicly commented on the specific incidents as of Tuesday. Regional cybersecurity agencies are reportedly coordinating to assess the full scope of the intrusion and identify any compromised systems that may require immediate remediation.

Questions remain regarding the specific objectives of the data being sought and whether the malware has been used to conduct further operations beyond initial access. The campaign highlights the increasing sophistication of state-sponsored actors targeting emerging markets in aviation and finance, raising concerns about the vulnerability of critical supply chains in the region.

Discussion

0 / 2000