Mirage Kitten targets Middle East and Africa region with new malware

2026-07-28T08:51:45Z100058492375027194ff011fd4f90301e384ed68297d5cea7e29398b730d9bdd
APTAfricaBitLockerBrazilDNS-C2KazakhstanMicrosoft-GraphMiddle-EastOAuthRussiaSoutheast-AsiaViPNetbackdoorcredential-theftcryptocurrencydata-exfiltrationdevice-code-phishingextortionindustrial-control-systemsmalwarephishingransomwarestealersupply-chain-attackthreat-intelligence

What happened

Kaspersky Securelist RSS entries covering July 2026 threat intelligence, including Mirage Kitten/UNC1549 malware, BitLocker extortion, Project CAV3RN C2 over Microsoft Graph and DNS, ViPNet update-system abuse, GoSerpent and OkoBot campaigns, industrial threats, device-code phishing, Armored Likho’s BusySnake Stealer, and compromise-assessment findings.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
100058492375027194ff011fd4f90301e384ed68297d5cea7e29398b730d9bdd
Enrichment time
2026-07-28T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.