ISLAMABAD: Cybersecurity company Kaspersky has uncovered a cyber espionage campaign by the threat actor known as “Mirage Kitten,” which has targeted organizations across the Middle East, Africa and Pakistan, including entities in Pakistan’s aerospace and aviation sector.


According to Kaspersky’s latest report, the group is using a newly identified malware, dubbed NightLeader, which enables attackers to gain remote control of compromised computers. The malware is capable of accessing files, stealing sensitive data, capturing screenshots and maintaining covert access to targeted networks.


The report said the attackers relied on spear-phishing campaigns and fake job offers to lure victims into downloading malicious files, allowing them to infiltrate organizational systems.


Kaspersky also revealed evidence that covert tunneling tools were used following a cyberattack on a Pakistani aerospace and aviation organization, suggesting an effort by the attackers to establish persistent and hidden access within the victim’s network.


The cybersecurity firm warned that Mirage Kitten is employing increasingly sophisticated malware and tunneling techniques in its cyber espionage operations, posing a significant threat to government agencies and critical industries in the region.


In light of the findings, Kaspersky urged organizations to strengthen their cybersecurity posture by deploying advanced security solutions, including Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) platforms. It also recommended the use of threat intelligence services to improve early detection of cyber threats and enable a more effective incident response.


The company stressed that organizations should further enhance their security capabilities and response mechanisms to counter increasingly advanced cyber espionage campaigns.