PollCat is an obfuscated JavaScript, cross-platform remote-access trojan attributed with high confidence to the Iran-linked cyberespionage group Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It targets Windows, Linux, and macOS developer workstations and was distributed in trojanized React programming challenges presented as time-limited technical assessments by fraudulent recruiter personas on professional and job-search platforms. The implant starts during application initialization and contacts command-and-control infrastructure before completion of the lure’s purported one-time-password validation.
PollCat provides interactive shell access, execution of attacker-supplied JavaScript, hidden-process execution and process control, filesystem and directory operations, file upload and download, drive and mount-point enumeration, archive handling, and Windows DLL execution. It collects system, process, and software inventory and searches for artifacts associated with security and technology vendors. Persistence is established through scheduled tasks on Windows, cron on Linux, and cron and LaunchAgent mechanisms on macOS. Its C2 protocol uses a polling model and an unusual HTTP 400-based registration response handling pattern that overlaps with Mirage Kitten’s Retrograde/MiniFast backdoor.
Observed activity targeted software engineers and organizations in the fintech, aviation, and aerospace sectors, including victims in Afghanistan, Egypt, and Ethiopia. PollCat enables persistent espionage-oriented access to developer environments, including potential access to source code, repositories, credentials, and corporate services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A React-based challenge, RankChallenge-react, carried PollCat and displayed an attacker-controlled one-time-password screen; the malware registered with C2 and began polling while the application loaded.
A React-based challenge, RankChallenge-react, carried PollCat and displayed an attacker-controlled one-time-password screen; the malware registered with C2 and began polling while the application loaded.
PollCat is a separate cross-platform RAT written in obfuscated JavaScript and distributed through another trojanized coding challenge.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
“The first line of server.js imported a malicious npm package named colorized_terminal... attackers bundled it directly inside the archive's node_modules directory.”
It establishes persistence through ... cron entries on Linux, and cron ... mechanisms on macOS...
NodeRabbit gathers host and network details, lists processes, runs shell commands... PollCat provides ... shell access, and arbitrary JavaScript execution.
PollCat est un RAT multiplateforme écrit en JavaScript obfusqué.
“NodeRabbit can create an extension masquerading as GitHub Copilot Helper,” and actors “incorporated a targeted organization's name into Azure subdomains.”
T1016 — System Network Configuration Discovery (Discovery).
“Implemented functionality includes... process enumeration and termination.”
NodeRabbit gathers host and network details... PollCat provides file transfers, system inventory...
“Implemented functionality includes directory enumeration... [and] drive and volume enumeration.”
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform remote-access trojan that supports file transfer, system inventory, hidden process execution, shell access, and arbitrary JavaScript execution. It persists via Windows scheduled tasks, Linux cron, and macOS cron or LaunchAgent mechanisms, and checks for security-product traces.
An obfuscated JavaScript cross-platform remote-access trojan delivered in a trojanized React coding assessment. It registers with C2 and polls for commands independently of the lure's OTP authentication flow. It persists through Windows scheduled tasks, Linux cron, and macOS cron/LaunchAgents, and supports system inventory, file and process operations, command execution, file transfer, archive handling, DLL execution on Windows, hidden execution, and arbitrary JavaScript execution.
A JavaScript/Node.js-based implant disguised as a time-limited React coding assessment. It initiates command-and-control communications when the local application loads, before the victim enters the purported recruiter-provided access code.
A cross-platform JavaScript remote-access trojan that persists using daily scheduled tasks on Windows, Linux, and macOS. It registers with C2 infrastructure and supports file operations, shell-command execution, file upload/download, JavaScript execution, DLL loading, ZIP archive creation/extraction, and host/process/storage enumeration. It also inventories root contents of folders associated with numerous software and security vendors and exfiltrates the results as JSON.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.