Infected Hosts Become Covert Operator Relays

A single compromise can become a hidden pivot point. Mirage Kitten is using infected machines to carry operator traffic, so the real problem is not just the backdoor on the endpoint but the internal network path that host now relays. Kaspersky disclosed a previously undocumented set made up of the NightLedger Windows backdoor and two WebSocket tunnelers, ArcBridge and BridgeHead. BridgeHead was seen in post-exploitation in Egypt and at a Pakistan aerospace and aviation organization, which shows the relay tools are already in use, not just on paper. That shifts cleanup away from the obvious endpoint and toward the traffic the host may now be forwarding. For defense, telecommunications, aviation, government, and financial-sector teams across the Middle East, Africa, and South Asia, the compromise can persist as a stealthy relay even after the initial backdoor is found.

Part of the PlainSec briefing for 2026-07-28

Sources