← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

NightLedger investigation separates observed tooling from attribution

Kaspersky reports a previously undocumented Windows backdoor and two tunneling tools associated with Mirage Kitten.

Source published 2026-07-28Threat researchResearch briefing
Original publication preview: NightLedger investigation separates observed tooling from attribution
Kaspersky / Securelist ↗

Findings and evidence

Kaspersky reports a previously undocumented Windows backdoor and two tunneling tools associated with Mirage Kitten. Its findings connect malware analysis with observations from aerospace and other targeted environments in the Middle East and surrounding regions.

Why it matters

A useful forensic timeline combines host activity with the network path used to reach shared services. Record evidence for each association instead of treating a malware-family label as a complete incident explanation.

Scope and limits

The initial access route was unclear for many samples. The source’s attribution and geographic picture reflect available observations, with those limitations explicitly retained.

Primary source

Kaspersky / Securelist: original publication. Source published 2026-07-28. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC