Iran-linked risk actor Mirage Kitten is concentrating on software program builders with faux recruitment assessments that disguise two newly recognized cross-platform distant entry trojans: NodeRabbit and PollCat.
The marketing campaign makes use of recruiter impersonation on LinkedIn and different job-search platforms, weaponized Node.js initiatives, and cloud-hosted ZIP archives to realize covert entry to developer endpoints throughout Home windows, Linux, and macOS.
Telemetry linked the exercise to fintech, aviation, and aerospace targets throughout the Center East and Africa, whereas malicious mission archives have been additionally submitted to public scanning providers from India, Türkiye, Israel, Iraq, Germany, and Eire.
The an infection chain begins with a faux recruiter providing a technical function and sending a time-sensitive coding problem. One archive, Entrance-Technical-Problem.zip, introduced a legitimate-looking TaskFlow software constructed with Categorical, React, and Vite.
Its README instructed candidates to repair front-end defects whereas explicitly claiming that server.js was protected and shouldn’t be modified directing scrutiny away from the tampered file.
The malicious server.js imported colorized_terminal model 2.1.0, a trojanized bundle bundled domestically in node_modules relatively than downloaded from npm.
When the sufferer ran the mission, the bundle launched a hid NodeRabbit payload from node_modules/.cache/.320697f1/index.js as a indifferent course of. Different samples used a equally weaponized bundle named pretty-log.
This social-engineering mannequin is especially efficient in opposition to builders: the evaluation seems to require regular setup steps akin to npm set up and software execution, whereas synthetic deadlines and directions to not use AI assistants discourage code overview.
Kaspersky famous that an AI-based or guide audit might have uncovered the suspicious bundle import.
NodeRabbit is a Node.js-based RAT able to working throughout Home windows, Linux, and macOS.
It generates a host-specific identifier from system attributes together with hostname, username, operating-system information, structure, and MAC handle, then establishes persistence utilizing operating-system-native mechanisms.
On Home windows, early variants copied themselves into directories disguised as Microsoft Edge Replace or Intel Driver & Assist Assistant elements, paired a renamed node.exe binary with a JavaScript payload, and created Registry Run keys or scheduled duties.
Linux variants used cron @reboot entries, whereas macOS variants created LaunchAgents.
Mirage Kitten Marketing campaign
The implant communicates with Azure-hosted command-and-control infrastructure utilizing encrypted JSON requests protected with AES-256-GCM.
Kaspersky researchers first recognized NodeRabbit on a sufferer system in Afghanistan, then uncovered extra superior variants in Egypt and Ethiopia.
Operators can gather system and community data, enumerate processes, run shell instructions, learn and write information, alter beacon intervals, and execute arbitrary Node.js scripts.
Later NodeRabbit builds added proxy discovery and authentication help, anti-analysis checks, and developer-focused persistence by a faux VS Code extension branded as “GitHub Copilot Helper” and malicious Git post-merge or post-checkout hooks.
PollCat, the second newly documented malware household, is an obfuscated JavaScript RAT delivered in a separate React-based evaluation named RankChallenge-react.
.env file (Supply : Kaspersky).The lure makes use of recruiter-supplied, short-lived OTP codes and a one-hour completion window, however the malware begins within the background throughout software startup earlier than the sufferer enters a code.
After registration, PollCat can stock the host, execute instructions, listing and delete information, enumerate drives and operating processes, switch information in both path, begin hidden processes, and execute attacker-provided JavaScript.
Its SYSTEM_CHECK routine inventories software program and security-product-related directories, together with paths related to Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, Fortinet, Sophos, and Kaspersky.
PollCat’s C2 design additionally overlaps with the group’s earlier Retrograde/MiniFast tooling: each deal with an HTTP 400 response as a profitable session handshake, extract a socketId, and use that worth for command polling.
The shared protocol construction, equivalent default beacon timing, victimology, and recurring use of Azure Web sites and Cloudflare-backed domains underpin Kaspersky’s high-confidence attribution to Mirage Kitten.
The marketing campaign marks a big shift for Mirage Kitten, which beforehand favored native C, C++, and Go malware usually delivered by DLL search-order hijacking.
NodeRabbit and PollCat as a substitute mix into fashionable developer workflows by abusing Node.js dependencies, JavaScript execution, IDE extensions, Git hooks, and cloud-hosted evaluation information.
Organizations ought to deal with unsolicited coding challenges as untrusted software program, isolate assessments in disposable environments.
Examine bundled dependencies earlier than execution, monitor for surprising Node.js processes and new scheduled duties, and overview Git hooks and VS Code extension directories.
Kaspersky detects the exercise as Trojan.JS.MirageKitten.*.
IOCs
| Kind | Area |
|---|---|
| Area | oracle-challenge.s3.us-east-1.amazonaws.com |
| Area | naturalapplication.azurewebsites.web |
| Area | retaildemo.azurewebsites.web |
| Area | tubitak.azurewebsites.web |
| Area | rgbteller.azurewebsites.web |
| Area | wslwebui.azurewebsites.web |
| Area | plugplay.azurewebsites.web |
| Area | crossdwm.azurewebsites.web |
| Area | wdisystem.azurewebsites.web |
| Area | wslmenus.azurewebsites.web |
| Area | dnshnsdev.azurewebsites.web |
| Area | hpjumpsrv.azurewebsites.web |
| Area | storview.azurewebsites.web |
| Area | healthcomfsdpower.com |
Notice: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintended decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms akin to MISP, VirusTotal, or your SIEM.
★ Which Safety Instruments Ought to You Lower? Rating Them on One Web page – Obtain the Inherited Safety Stack Information






