Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
On Linux, NodeRabbit creates an @reboot cron entry... PollCat appends both a daily 09AM cron line and an @reboot line.
Variant 2 creates a scheduled task named IntelDriverSupportUpdate, which runs daily at 10AM... PollCat creates a daily task named NetSync_<username>.
NodeRabbit proc:start executes an arbitrary shell command; PollCat RUN executes a shell command.
On Linux, NodeRabbit creates an @reboot cron entry... PollCat appends both a daily 09AM cron line and an @reboot line.
On Linux, NodeRabbit creates an @reboot cron entry... PollCat appends both a daily 09AM cron line and an @reboot line.
NodeRabbit supports proc:list. PollCat supports TASKLIST and SYSTEM_CHECK, which collects the names of running processes.
NodeRabbit's sys:info returns hostname, domain user information, username, and process ID. PollCat's /gate/hello submits host, user, domain, OS information, and current privilege level.
NodeRabbit chooses from Azure-hosted C2 infrastructure addresses; on failure, it switches to the next C2 address. PollCat iterates over C2s until registration succeeds.
NodeRabbit communicates with command-and-control servers through API endpoints... PollCat registers through POST /beacon, polls GET /gate/fetch, and submits results through POST /gate/submit.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cross-platform, obfuscated JavaScript remote-access trojan delivered through a fake React programming assessment. It begins C2 registration during application loading, can persist after valid OTP authentication, and supports command execution, process and file management, file transfer, DLL execution on Windows, JavaScript execution supplied by C2, archive operations, and host/security-software inventory collection. It uses polling-based C2 with a socketId session token and OS-specific scheduled-task, cron, and LaunchAgent persistence.
A JavaScript-based cross-platform RAT delivered inside a fake React programming assessment. It persists through scheduled tasks, cron, and macOS LaunchAgents; registers and polls its C2 using an unusual HTTP 400-based handshake; supports command execution, file and directory operations, process enumeration/termination, file upload and download, DLL execution on Windows, JavaScript execution supplied by C2, and security/software inventory collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.