Official MENA TECH logo<br>

A cyber espionage campaign utilizing new malware targets organizations in the Middle East and Africa

Editors Team

Cybersecurity researchers have uncovered a sophisticated, previously undocumented malware suite utilized by the Advanced Persistent Threat (APT) group known as Mirage Kitten. This announcement came during Kaspersky’s Gannual Cyber Security Weekend for the META region, which was covered by the MENA TECH team. The campaign was engineered to establish persistent, long-term access inside targeted enterprise environments to extract sensitive intelligence.

Kaspersky researchers mapped campaign intrusions targeting high-value organizations across Africa and the Middle East, including:

  • Jordan & Tanzania: Government ministries and small-to-medium businesses.

  • Egypt: Enterprise-level post-compromise targets.

  • Pakistan: Aerospace and aviation sector organizations.

  • Ethiopia: Telecommunications providers.

  • Burkina Faso: Financial sector entities.

The newly exposed toolset consists of three custom-coded components designed for persistent remote execution and network traversal:

  • NightLedger: A newly identified Windows backdoor providing full remote access capabilities. It allows operators to execute arbitrary commands, navigate local directories, exfiltrate files, and capture screen states.

  • ArcBridge & BridgeHead: A pair of covert tunneling applications engineered to turn infected endpoints into passive relay nodes. By funneling attack traffic directly through the victim’s local machine, external server traffic appears native to the internal network, effectively bypassing security controls and perimeter monitoring.

The earliest telemetry tracking ArcBridge dates back to April 2026. Investigations into post-compromise activity revealed that initial access relied heavily on social engineering, including spear-phishing lures disguised as trusted recruitment platforms and fraudulent videoconferencing landing pages redirecting users to host archive files containing the malware payloads.

Omar Amin, Senior Security Researcher at Kaspersky GReAT, noted: “Mirage Kitten continues to evolve its malware arsenal in support of targeted cyber-espionage operations. In practice, their reliance on tunneling utilities enables attackers to bypass network controls, maintain covert access, and significantly complicate detection efforts. Organizations should incorporate these findings into their threat assessments.”

THE BRIEF - Curated regional news every Monday
MENA TECH’s weekly newsletter keeps you updated on all major tech and business news.
By subscribing, you confirm you are 18+ years old, will receive newsletter and promotional content, and agree to our terms of use and privacy policy. You may unsubscribe at any time.
Read More
MENA TECH – The leading Arabic-language media platform for technology and business
MENA TECH – The leading Arabic-language media platform for technology and business
Copyright © 2026 MenaTech. All rights reserved.