ISLAMABAD: Cybersecurity researchers have uncovered a new cyber-espionage campaign linked to the Mirage Kitten advanced persistent threat (APT) group, with organizations in Pakistan’s aviation and aerospace sector among the targeted victims.
According to cybersecurity firm Kaspersky’s Global Research and Analysis Team (GReAT), the previously undocumented malware toolkit has been used in targeted attacks aimed at maintaining long-term access to compromised networks and stealing sensitive information.
The campaign has affected organizations across the Middle East and Africa, including government entities, small and medium-sized businesses, telecommunications companies and financial sector organizations in several countries.
Kaspersky researchers identified a new Windows backdoor named NightLedger, which they attributed to Mirage Kitten based on similarities in code and attack behaviour with the group’s previously known malware. The backdoor enables attackers to remotely control infected systems, execute commands, access files, transfer data and capture screenshots.
The researchers also identified two additional tools, ArcBridge and BridgeHead, designed for covert tunnelling operations. These tools allow attackers to route malicious traffic through compromised systems, helping them bypass security controls and maintain hidden access inside targeted networks.
Kaspersky said BridgeHead was observed during post-compromise activity in victim environments, including an aerospace and aviation organization in Pakistan. Researchers noted that the attacks involved targeted spear-phishing attempts using highly customized lures, including fake recruitment messages impersonating trusted brands and hiring platforms, as well as fraudulent video conferencing pages directing users to malicious files.

Omar Amin, Senior Security Researcher at Kaspersky GReAT, said Mirage Kitten continues to expand its malware capabilities to support targeted cyber-espionage operations across the Middle East and Africa.
He added that the group’s continued use of tunnelling tools highlights a growing challenge for organizations, as such techniques allow attackers to evade network monitoring, maintain covert access and complicate detection efforts.
Kaspersky advised organizations to strengthen threat detection and response measures, remain vigilant against suspicious emails and phishing attempts, and improve monitoring of advanced cyber threats.
The cybersecurity firm recommended using advanced security solutions, including endpoint detection and response (EDR) and extended detection and response (XDR) capabilities, along with threat intelligence services to identify and respond to sophisticated cyberattacks.
The discovery highlights growing cybersecurity risks facing critical sectors, including aviation and aerospace, as threat groups increasingly use advanced malware and stealth techniques to target sensitive networks.
Also Read: 12.2% of Users in Pakistan Attacked by Online Threats in First Half of 2026: Kaspersky


Today's E-Paper