
Findings and evidence
Kaspersky reports a previously undocumented Windows backdoor and two tunneling tools associated with Mirage Kitten. Its findings connect malware analysis with observations from aerospace and other targeted environments in the Middle East and surrounding regions.
Why it matters
A useful forensic timeline combines host activity with the network path used to reach shared services. Record evidence for each association instead of treating a malware-family label as a complete incident explanation.
Scope and limits
The initial access route was unclear for many samples. The source’s attribution and geographic picture reflect available observations, with those limitations explicitly retained.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-07-28. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.