Threat Briefing
Briefing 49: Persistent Targeting: An Analysis of Mirage Kitten’s Campaigns Against the Global Aerospace Sector
Originally published by Space ISAC. Read the original article here.
Overview
Cyber threats to the space and aerospace sectors are increasingly shaped by sophisticated espionage operations that receive less attention than disruptive ransomware and hacktivist campaigns but pose significant long-term risks to sensitive technologies, intellectual property and mission-critical systems. Among the most persistent actors targeting the sector is Mirage Kitten, an Iran-nexus threat actor also tracked as UNC1549, Nimbus Manticore and Smoke Sandstorm.
Active since at least 2022, Mirage Kitten emerged as a notable aerospace threat in 2024, when Mandiant documented suspected Iranian espionage activity targeting aerospace, aviation and defense organizations across Israel, the UAE and potentially Turkey, India and Albania. Researchers assessed the activity with moderate confidence as UNC1549 and identified overlaps with other Iran-linked clusters associated with the Islamic Revolutionary Guard Corps (IRGC).
Since then, Mirage Kitten and closely overlapping activity clusters have demonstrated a persistent interest in aerospace, defense, aviation and telecommunications organizations. Rather than relying on opportunistic exploitation, the actor frequently conducts extensive reconnaissance, develops highly tailored social-engineering campaigns and deploys custom malware designed to maintain covert access. This combination makes Mirage Kitten a particularly relevant espionage threat to space-sector organizations and their broader supply chains.
Operation Dream Job
Recruitment-themed social engineering has become one of the most recognizable components of Mirage Kitten-associated tradecraft. In November 2024, ClearSky disclosed an Iranian campaign attributed to TA455, an activity cluster with significant overlap with Mirage Kitten, targeting aerospace personnel through fraudulent employment opportunities. Operators impersonated recruiters on LinkedIn, established convincing recruitment websites and delivered malicious files disguised as job-related materials. The campaign deployed the SnailResin loader and SlugResin backdoor through DLL sideloading.
Although recruitment-themed operations are not unique to Iranian actors, their continued use demonstrates Mirage Kitten’s emphasis on exploiting trusted professional relationships. Later campaigns combined highly tailored phishing with abuse of third-party relationships, including attempts to pivot from service providers into customer environments. This creates particular risk for aerospace and space organizations, where contractors, engineering firms, technology providers and other suppliers routinely maintain trusted access across interconnected environments.
Expanding Scope of Targeting
Mirage Kitten’s targeting has gradually expanded beyond its initial concentration on Middle Eastern aerospace and defense organizations. By September 2025, researchers documented closely overlapping activity that compromised 34 devices across 11 organizations in Canada, France, the UAE, the United Kingdom and the United States. The campaign primarily targeted telecommunications organizations but maintained the actor’s broader interest in aerospace and defense. Operators conducted extensive reconnaissance against researchers, developers and IT administrators before approaching selected personnel through fake LinkedIn recruitment profiles.
The activity also demonstrated the group’s continued preference for legitimate services and trusted infrastructure. Malware communicated with command-and-control infrastructure proxied through Microsoft Azure, while signed applications and DLL sideloading helped malicious execution blend with legitimate system activity.
Acceleration During Regional Conflict
Mirage Kitten activity accelerated again in early 2026 amid escalating tensions involving Iran, Israel and the United States. Check Point observed new phishing activity beginning in February and subsequently documented multiple campaign waves during the conflict, including activity targeting aviation and software organizations across the United States, Europe and the Middle East. The actor introduced new delivery and execution techniques, including SEO poisoning and abuse of legitimate application workflows, while continuing to rely on career-themed social engineering.
Most notably, the actor resurfaced during Operation Epic Fury with newly developed capabilities, including the MiniFast backdoor. Check Point assessed that characteristics of MiniFast were consistent with AI-assisted development, potentially enabling operators to accelerate malware development and modification during a rapidly evolving conflict.
Evolving TTPs and Capabilities
Despite frequent changes to individual payloads, Mirage Kitten maintains several recognizable behavioral patterns. Nextron Systems observed the group abusing legitimate applications and trusted cloud infrastructure while rotating infection mechanisms between campaigns. Previous activity relied heavily on DLL sideloading and DLL search-order hijacking; more recent campaigns incorporated AppDomain hijacking, allowing malicious code to execute through trusted .NET applications and attacker-controlled configuration files.
These changes demonstrate incremental adaptation rather than wholesale shifts in tradecraft. Operators continue to use carefully constructed recruitment personas and trusted applications while modifying loaders, encryption, obfuscation and execution techniques to complicate detection.
Most Recent Activity
The group’s continued development was reinforced on 28 July 2026, when Kaspersky disclosed a previously undocumented Mirage Kitten malware suite. The tooling included NightLedger, a Windows backdoor supporting reconnaissance, command execution, file operations, process discovery and screenshot capture, alongside two custom WebSocket tunnelers, ArcBridge and BridgeHead, designed to provide covert network access.
BridgeHead was observed during post-exploitation activity in Egypt and at a Pakistan-based aerospace and aviation organization, indicating that the group’s tooling extends beyond initial compromise toward sustained access and internal network operations. Kaspersky also identified victims across the Middle East and Africa and noted the group’s continued reliance on tunneling utilities and evolving command-and-control infrastructure.
In context, this activity underscores that Mirage Kitten’s interest in aerospace is neither incidental nor short-lived. Its sustained targeting, tailored social engineering, exploitation of trusted relationships, evolving malware and responsiveness to geopolitical events indicate a persistent espionage requirement. For space organizations and their suppliers, the threat extends beyond phishing awareness to protecting privileged personnel, third-party relationships, engineering environments and trusted applications that sophisticated actors can exploit to establish long-term access.
Originally published by Space ISAC. Read the original article here.