Skip to main content
← All threats
CRITICAL Published August 4, 2026

NightLedger Backdoor Deployed in Espionage Campaign Targeting the Middle East and Africa

An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

An advanced persistent threat group, Mirage Kitten, is conducting cyber-espionage operations across the Middle East and Africa using three previously undocumented malware families: NightLedger, BridgeHead, and ArcBridge. These tools provide reconnaissance, command execution, covert tunneling, and persistent access capabilities. The campaign targets organizations in Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso across aerospace, aviation, defense, telecommunications, government, financial services, and SMB sectors. Initial access is gained through targeted spear-phishing with recruitment-themed lures and fake videoconferencing pages. The malware demonstrates sophisticated operational security features including victim-specific execution controls, WebSocket-based tunneling, and Cloudflare-backed infrastructure, reflecting the group's investment in bespoke tooling for long-term intelligence collection.

MITRE ATT&CK

Tactics, Techniques & Procedures

TA0011 Command and Control tactic
TA0001 Initial Access tactic
TA0008 Lateral Movement tactic
TA0003 Persistence tactic

Defensive mapping

Mapped controls

The audit will verify each of these controls is in place and effective.

Control Confidence Why it matters
EDR with behavioural detection suggested 75% Recommended control for apt
Network segmentation between user and server tiers suggested 75% Recommended control for apt
PAM suggested 75% Recommended control for apt
Threat hunting suggested 75% Recommended control for apt
Log retention and SIEM suggested 75% Recommended control for apt