BridgeHead is a custom Windows WebSocket-based tunneling utility associated with the Iranian state-aligned espionage group Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It is used during post-exploitation to provide covert operator-controlled network access through compromised hosts. The malware functions as a full SOCKS5 tunnel proxy, relaying attacker-directed traffic through victim systems so connections appear to originate from the compromised environment. BridgeHead has also been observed handling enterprise proxy authentication by leveraging the current user’s Windows single sign-on context, indicating design choices suited for operation inside corporate networks.
BridgeHead is tailored for stealth and victim-specific deployment. Observed samples validate the current Windows username against a hardcoded value or substring before activating, a control likely intended to restrict execution to intended targets and reduce exposure during automated analysis. It receives binary commands over a WebSocket channel initiated by its command-and-control infrastructure, which directs tunnel creation and traffic forwarding. Reported activity places BridgeHead in intrusions against organizations in Egypt and Pakistan, including aerospace and aviation targets, as part of a broader cyber-espionage campaign affecting government, telecommunications, financial, defense, and related sectors across the Middle East and Africa.
BridgeHead is part of a broader bespoke toolset that includes the NightLedger backdoor and the ArcBridge tunneling utility. Its deployment has been linked to targeted spearphishing operations using recruitment-themed social-engineering lures and fake videoconferencing pages that delivered follow-on payloads. Functionally, BridgeHead overlaps with other Mirage Kitten tunneling tools and reflects the group’s continued emphasis on maintaining long-term covert access and flexible internal network reach after initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kaspersky also identified BridgeHead, a custom WebSocket tunneling utility deployed during post-exploitation activity. The malware functions as a full SOCKS5 tunnel proxy, forwarding attacker-controlled traffic through compromised systems while supporting enterprise proxy authentication using Windows single sign-on credentials.
Two other malware families delivered as part of the attacks are BridgeHead ("unbcl.dll"), a SOCKS5 tunnel proxy observed in environments in Egypt and Pakistan...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Mirage Kitten continues to rely on highly targeted spear-phishing, recruitment-themed lures, and fake videoconferencing pages to gain initial access before deploying custom malware.
The phishing activity employed carefully crafted recruitment-themed lures impersonating trusted employers and hiring platforms, alongside lookalike videoconferencing websites that redirected victims to malicious archives hosted on third-party file-sharing services.
The malware dynamically loads advapi32.dll, resolves GetUserNameA ... Notably ... another variant ... shares the same dynamic-resolve stub pattern.
The malware provides remote access, command execution, file management, and covert communication to maintain persistence and evade detection.
NightLedger periodically contacts its C2 over HTTPS ... establishes an HTTPS WebSocket connection ... communicates with businessmixture.com/blog over WSS on port 443
Kaspersky also identified BridgeHead, a custom WebSocket tunneling utility deployed during post-exploitation activity. The malware functions as a full SOCKS5 tunnel proxy, forwarding attacker-controlled traffic through compromised systems...
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom WebSocket-based tunneling utility used post-exploitation. It acts as a full SOCKS5 proxy, forwards attacker traffic through compromised hosts, supports enterprise proxy authentication via Windows SSO credentials, and includes victim-specific execution checks based on Windows username.
A custom WebSocket/SOCKS5 tunneling utility used to relay operator traffic through victim machines. The C2 initiates tunnel connections over WebSocket and the implant forwards traffic between server-specified targets and the WebSocket channel, making the victim host a relay node.
A custom WebSocket-based tunneling implant attributed to Mirage Kitten that establishes authenticated WSS connections, handles enterprise proxy authentication including Negotiate and NTLM, and functions as a full SOCKS5 relay so operators can tunnel traffic through victim hosts.
A custom WebSocket-based SOCKS5 tunnel proxy used in post-exploitation by Mirage Kitten. It performs username-based execution gating, establishes authenticated HTTPS WebSocket connections, handles enterprise proxy authentication including Negotiate and NTLM, and relays operator-directed traffic through victim networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.