Mirage Tiger, also tracked as the WiseGuy activity cluster, is a cyber espionage threat actor with a suspected nexus to India. The group has been observed conducting targeted intrusion campaigns since at least 2017, primarily focusing on government and military-related entities in Pakistan, with a clear objective of intelligence gathering. Mirage Tiger distinguishes itself through its consistent targeting of specific regional adversaries and its state-sponsored motivation, employing custom malware and exploiting zero-day vulnerabilities in its operations. Community identifiers for this group also include Orange Dev 1 and Confucius.