• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Mirage Kitten Hackers Use Faux Coding Challenges to Deploy NodeRabbit and PollCat RATs

Admin by Admin
September 2, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Iran-linked risk actor Mirage Kitten is concentrating on software program builders with faux recruitment assessments that disguise two newly recognized cross-platform distant entry trojans: NodeRabbit and PollCat.

The marketing campaign makes use of recruiter impersonation on LinkedIn and different job-search platforms, weaponized Node.js initiatives, and cloud-hosted ZIP archives to realize covert entry to developer endpoints throughout Home windows, Linux, and macOS.

Telemetry linked the exercise to fintech, aviation, and aerospace targets throughout the Center East and Africa, whereas malicious mission archives have been additionally submitted to public scanning providers from India, Türkiye, Israel, Iraq, Germany, and Eire.

The an infection chain begins with a faux recruiter providing a technical function and sending a time-sensitive coding problem. One archive, Entrance-Technical-Problem.zip, introduced a legitimate-looking TaskFlow software constructed with Categorical, React, and Vite.

Its README instructed candidates to repair front-end defects whereas explicitly claiming that server.js was protected and shouldn’t be modified directing scrutiny away from the tampered file.

The malicious server.js imported colorized_terminal model 2.1.0, a trojanized bundle bundled domestically in node_modules relatively than downloaded from npm.

When the sufferer ran the mission, the bundle launched a hid NodeRabbit payload from node_modules/.cache/.320697f1/index.js as a indifferent course of. Different samples used a equally weaponized bundle named pretty-log.

This social-engineering mannequin is especially efficient in opposition to builders: the evaluation seems to require regular setup steps akin to npm set up and software execution, whereas synthetic deadlines and directions to not use AI assistants discourage code overview.


README file for a trojanized coding challenge app (Source : Kaspersky).
README file for a trojanized coding problem app (Supply : Kaspersky).

Kaspersky famous that an AI-based or guide audit might have uncovered the suspicious bundle import.

NodeRabbit is a Node.js-based RAT able to working throughout Home windows, Linux, and macOS.

It generates a host-specific identifier from system attributes together with hostname, username, operating-system information, structure, and MAC handle, then establishes persistence utilizing operating-system-native mechanisms.

On Home windows, early variants copied themselves into directories disguised as Microsoft Edge Replace or Intel Driver & Assist Assistant elements, paired a renamed node.exe binary with a JavaScript payload, and created Registry Run keys or scheduled duties.

Linux variants used cron @reboot entries, whereas macOS variants created LaunchAgents.

Mirage Kitten Marketing campaign

The implant communicates with Azure-hosted command-and-control infrastructure utilizing encrypted JSON requests protected with AES-256-GCM.

Kaspersky researchers first recognized NodeRabbit on a sufferer system in Afghanistan, then uncovered extra superior variants in Egypt and Ethiopia.

Operators can gather system and community data, enumerate processes, run shell instructions, learn and write information, alter beacon intervals, and execute arbitrary Node.js scripts.

Later NodeRabbit builds added proxy discovery and authentication help, anti-analysis checks, and developer-focused persistence by a faux VS Code extension branded as “GitHub Copilot Helper” and malicious Git post-merge or post-checkout hooks.

PollCat, the second newly documented malware household, is an obfuscated JavaScript RAT delivered in a separate React-based evaluation named RankChallenge-react.

.env file (Source : Kaspersky).
.env file (Supply : Kaspersky).

The lure makes use of recruiter-supplied, short-lived OTP codes and a one-hour completion window, however the malware begins within the background throughout software startup earlier than the sufferer enters a code.

After registration, PollCat can stock the host, execute instructions, listing and delete information, enumerate drives and operating processes, switch information in both path, begin hidden processes, and execute attacker-provided JavaScript.

Its SYSTEM_CHECK routine inventories software program and security-product-related directories, together with paths related to Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, Fortinet, Sophos, and Kaspersky.

PollCat’s C2 design additionally overlaps with the group’s earlier Retrograde/MiniFast tooling: each deal with an HTTP 400 response as a profitable session handshake, extract a socketId, and use that worth for command polling.

The shared protocol construction, equivalent default beacon timing, victimology, and recurring use of Azure Web sites and Cloudflare-backed domains underpin Kaspersky’s high-confidence attribution to Mirage Kitten.

The marketing campaign marks a big shift for Mirage Kitten, which beforehand favored native C, C++, and Go malware usually delivered by DLL search-order hijacking.

NodeRabbit and PollCat as a substitute mix into fashionable developer workflows by abusing Node.js dependencies, JavaScript execution, IDE extensions, Git hooks, and cloud-hosted evaluation information.

Organizations ought to deal with unsolicited coding challenges as untrusted software program, isolate assessments in disposable environments.

Examine bundled dependencies earlier than execution, monitor for surprising Node.js processes and new scheduled duties, and overview Git hooks and VS Code extension directories.

Kaspersky detects the exercise as Trojan.JS.MirageKitten.*.

IOCs

Kind Area
Area oracle-challenge.s3.us-east-1.amazonaws.com
Area naturalapplication.azurewebsites.web
Area retaildemo.azurewebsites.web
Area tubitak.azurewebsites.web
Area rgbteller.azurewebsites.web
Area wslwebui.azurewebsites.web
Area plugplay.azurewebsites.web
Area crossdwm.azurewebsites.web
Area wdisystem.azurewebsites.web
Area wslmenus.azurewebsites.web
Area dnshnsdev.azurewebsites.web
Area hpjumpsrv.azurewebsites.web
Area storview.azurewebsites.web
Area healthcomfsdpower.com

Notice: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintended decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms akin to MISP, VirusTotal, or your SIEM.

★ Which Safety Instruments Ought to You Lower? Rating Them on One Web page – Obtain the Inherited Safety Stack Information

Tags: ChallengesCodingDeployFakeHackersKittenMirageNodeRabbitPollCatRATs
Admin

Admin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026
These 5 Easy Methods Helped Me Construct a Smarter House

These 5 Easy Methods Helped Me Construct a Smarter House

July 19, 2025
Arbitrage: Environment friendly Reasoning by way of Benefit-Conscious Hypothesis

Arbitrage: Environment friendly Reasoning by way of Benefit-Conscious Hypothesis

August 8, 2026
Scientists rework peacock feathers into tiny organic laser beams

Scientists rework peacock feathers into tiny organic laser beams

August 4, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Mirage Kitten Hackers Use Faux Coding Challenges to Deploy NodeRabbit and PollCat RATs

Mirage Kitten Hackers Use Faux Coding Challenges to Deploy NodeRabbit and PollCat RATs

September 2, 2026
LLMs Are Not (Persistently) Bayesian: Quantifying Inside (In)consistencies of LLMs’ Probabilistic Beliefs

LLMs Are Not (Persistently) Bayesian: Quantifying Inside (In)consistencies of LLMs’ Probabilistic Beliefs

September 2, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved