Cybersecurity researchers are warning aviation organizations to harden their networks against a sophisticated threat actor that has been quietly compromising targets across the Middle East and Africa. The advisory follows the discovery of previously unknown malware tied to the Mirage Kitten advanced persistent threat (APT) group, which has been linked to a campaign designed for long-term network access and data theft. Main Developments Kaspersky's Global Research and Analysis Team (GReAT) uncovered the new malware set during an investigation into Mirage Kitten's activities. The tools were deployed to maintain persistent access to victim networks and exfiltrate sensitive information. Researchers identified victims across several countries, including organizations in Egypt, small and medium-sized businesses and government entities in Jordan and Tanzania, telecom companies in Ethiopia, and financial-sector firms in Burkina Faso. The campaign's geographic spread highlights the group's broad operational reach. Read also: Pakistan's BOA charts SEZ reforms to spur investment growth Omar Amin, a senior security researcher at Kaspersky GReAT, noted that Mirage Kitten continues to evolve its malware arsenal to support targeted cyber-espionage. He emphasized the group's reliance on tunneling utilities, which allow attackers to bypass network controls and maintain covert access while evading detection. Background Mirage Kitten is a known APT group with a history of espionage-focused operations. The latest findings underscore its persistent evolution, as it refines its tools and techniques to stay ahead of defenders. The advisory comes amid growing global concern over cyber threats to critical infrastructure, including aviation. Previous incidents have shown that such attacks can disrupt operations and compromise sensitive data, making proactive defense essential. Why It Matters For aviation bodies and other organizations in the region, the findings serve as a critical reminder of the evolving threat landscape. The use of tunneling utilities complicates detection, meaning standard security measures may be insufficient. If left unaddressed, these vulnerabilities could lead to prolonged network compromise, data breaches, and operational disruptions. The advisory urges defenders to incorporate these insights into threat assessments and strengthen response capabilities. What's Next Organizations are advised to review their current security postures and integrate the new threat intelligence into their monitoring systems. Enhanced detection and response protocols will be key to mitigating risks from Mirage Kitten and similar groups. As the group continues to develop new tools, ongoing vigilance and collaboration between cybersecurity firms and sector stakeholders will be crucial to staying ahead of emerging threats.