ArcBridge is a custom WebSocket-based tunneling utility associated with the Iran-linked threat actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It has been used in long-term cyber-espionage operations targeting organizations across the Middle East and Africa, including entities in government, telecommunications, aviation, aerospace, defense, financial services, and small-to-medium business environments.
ArcBridge is designed for covert post-compromise network access through victim systems. It enables operators to establish remote proxy or tunnel sessions and perform DNS resolution via compromised hosts, allowing attacker-controlled traffic and name resolution to be relayed from inside victim environments. The malware uses WebSocket-based communications and includes an embedded configuration containing command-and-control connection parameters and an implant identifier. It also enforces single-instance execution through a mutex, indicating operational safeguards to avoid duplicate execution.
ArcBridge has been observed alongside other Mirage Kitten tooling, notably the NightLedger backdoor and the BridgeHead tunneling utility, as part of tailored intrusion sets intended to maintain persistent and covert access after initial compromise. In the broader campaign, Mirage Kitten commonly relied on highly targeted spearphishing, including recruitment-themed lures and fake videoconferencing pages delivering malicious archives, after which bespoke implants and tunnelers were deployed to support espionage objectives. ArcBridge reflects the actor’s continued investment in custom tunneling utilities for stealthy post-exploitation operations within victim networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers also documented ArcBridge, a second WebSocket-based tunneling utility first identified in April 2026... The utility enables operators to establish remote proxy sessions and perform DNS resolution through compromised hosts, expanding Mirage Kitten's ability to conduct covert post-compromise operations within victim environments.
...and ArcBridge, another WebSocket tunneling tool observed in April 2026 in activity targeting victims in the Middle East.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection.
NightLedger periodically contacts its C2 over HTTPS ... establishes an HTTPS WebSocket connection ... communicates with businessmixture.com/blog over WSS on port 443
Kaspersky also identified BridgeHead, a custom WebSocket tunneling utility deployed during post-exploitation activity. The malware functions as a full SOCKS5 tunnel proxy, forwarding attacker-controlled traffic through compromised systems...
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A WebSocket-based tunneling utility used for covert post-compromise operations. It uses a mutex to prevent multiple instances, embeds C2 and communication settings in its configuration, and enables remote proxy sessions and DNS resolution through compromised hosts.
A tunneling tool used to enable covert communication in support of persistence and evasion during long-term cyber-espionage operations.
A custom WebSocket tunneling tool used to maintain covert network access and operator-controlled tunneling in Nimbus Manticore intrusions.
A WebSocket tunneling tool attributed to Mirage Kitten that creates a single-instance mutex, uses an embedded configuration block for C2 settings, and supports operator-directed tunnel creation and DNS resolution over a WebSocket-style control channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.