Mirage Kitten is moving past simple footholds. Its new kit is built to keep an operator inside a victim network through hidden tunnels that look like normal web traffic, so the first phish is less important than the long-lived internal pivot that follows.
Kaspersky says the group has added NightLedger, a Windows backdoor, plus two previously undocumented WebSocket tunnelers, ArcBridge and BridgeHead. The tools were seen in Egypt and at a Pakistan-based aerospace and aviation organization, after spear-phishing lures tied to recruitment themes and fake videoconference pages.
That changes the defender problem from stopping a single compromise to spotting an interactive, operator-controlled foothold that can persist inside routine outbound traffic.