Mirage Kitten targets Middle East and Africa region with new malware
2026-07-28T08:51:45Z•100058492375027194ff011fd4f90301e384ed68297d5cea7e29398b730d9bdd
APTAfricaBitLockerBrazilDNS-C2KazakhstanMicrosoft-GraphMiddle-EastOAuthRussiaSoutheast-AsiaViPNetbackdoorcredential-theftcryptocurrencydata-exfiltrationdevice-code-phishingextortionindustrial-control-systemsmalwarephishingransomwarestealersupply-chain-attackthreat-intelligence
What happened
Kaspersky Securelist RSS entries covering July 2026 threat intelligence, including Mirage Kitten/UNC1549 malware, BitLocker extortion, Project CAV3RN C2 over Microsoft Graph and DNS, ViPNet update-system abuse, GoSerpent and OkoBot campaigns, industrial threats, device-code phishing, Armored Likho’s BusySnake Stealer, and compromise-assessment findings.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 100058492375027194ff011fd4f90301e384ed68297d5cea7e29398b730d9bdd
- Enrichment time
- 2026-07-28T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.