Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is an Iranian state-backed cyberespionage group active since at least 2022. It conducts long-term intelligence collection against aerospace, aviation, defense, telecommunications, financial services, and government organizations across the Middle East, Africa, and Europe. Confirmed victim environments include Egypt, Ethiopia, Afghanistan, Pakistan, Jordan, Tanzania, and Burkina Faso. The group uses highly targeted spear-phishing, recruiter impersonation, fraudulent recruitment portals, and lookalike videoconferencing pages to deliver malicious archives. It also targets software engineers through fake recruiter accounts on LinkedIn and other employment platforms, distributing trojanized coding assessments with malicious dependencies bundled inside otherwise legitimate-looking development projects. These assessments deliver NodeRabbit and PollCat, cross-platform Node.js and JavaScript remote-access trojans supporting Windows, Linux, and macOS. Their capabilities include command execution, host and network reconnaissance, process management, file collection and transfer, and persistent remote access. Persistence mechanisms include scheduled tasks, cron jobs, macOS LaunchAgents, Windows startup mechanisms, counterfeit Visual Studio Code extensions, and modified Git hooks. NodeRabbit variants additionally incorporate sandbox checks, authenticated enterprise-proxy support, encrypted command-and-control communications, and discovery of development projects and Outlook artifacts. Mirage Kitten's native malware toolkit includes Retrograde, also known as MiniFast, TWOSTROKE, and the NightLedger Windows backdoor. NightLedger uses DLL search-order hijacking and supports reconnaissance, screenshot capture, command execution, and file upload and download. The group's BridgeHead and ArcBridge WebSocket tunneling utilities provide covert operator-controlled network access through compromised systems; BridgeHead supports SOCKS5 traffic relay, enterprise single-sign-on proxy authentication, and victim-specific username checks. Mirage Kitten uses legitimate cloud infrastructure, including Microsoft Azure and Cloudflare-backed services, alongside custom tooling, masquerading, and anti-analysis controls to sustain access and evade detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
158 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting recruitment-themed social-engineering attacks against software developers. The group uses fake LinkedIn recruiter personas and malicious coding challenges to deliver cross-platform remote-access trojans, enabling reconnaissance, command execution, file manipulation, persistence, and access to developer source code, repositories, credentials, and corporate services.
Targets software developers with fake recruiter personas and malicious coding assessments distributed through LinkedIn and other employment platforms. Running the projects installs cross-platform remote access trojans that support reconnaissance, command execution, file manipulation, and persistence. The campaign has affected fintech, aviation, and aerospace organizations, with victims reported in Egypt, Ethiopia, and Afghanistan.
Iran-linked cyberespionage actor targeting software engineers at fintech, aviation, and aerospace organizations through fraudulent recruitment offers and trojanized coding assessments. The group uses cross-platform Node.js/JavaScript RATs and persists through developer workflows, including malicious Visual Studio Code extensions and Git hooks.
Conducting cyberespionage against fintech and aviation organizations in the Middle East and Africa by impersonating recruiters on LinkedIn and delivering trojanized coding assessments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.