Mirage Kitten targets Middle East and Africa region with new malware

2026-07-29T20:51:46Z988e2dfb6f747f9827e5cab0414a16d16dc3a23ea5211971516dd8236559c36d
APTArcBridgeBitLockerBridgeHeadC2DNS AAAAGoSerpentMSSQLMicrosoft GraphMirage KittenNightLedgerOkoBot cryptocurrencies thefters?Project CAV3RNRDPRMMSmoke SandstormStowaway RATUNC1549ViPNetcyber-espionagedata exfiltrationransomwaresupply-chain compromisethreat-intelligenceweb shells

What happened

Kaspersky Securelist threat intelligence feed covering July 2026 reporting on state-sponsored and criminal campaigns, including Mirage Kitten tooling, BitLocker extortion, Project CAV3RN C2 via Microsoft Graph and DNS AAAA records, ViPNet update-system abuse, GoSerpent and OkoBot malware, industrial control system threats, device-code phishing, Armored Likho’s BusySnake Stealer, and compromise-assessment findings. The material describes significant espionage, credential and cryptocurrency theft, ransomware/extortion, supply-chain, and ICS risks, but no specific CVEs are identified in the feed.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
988e2dfb6f747f9827e5cab0414a16d16dc3a23ea5211971516dd8236559c36d
Enrichment time
2026-07-29T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Mirage Kitten targets Middle East and Africa region with new malware · Baitaphish