Iran-linked Mirage Kitten targeted software engineers connected to fintech and aviation/aerospace organizations in Egypt, Ethiopia, and Afghanistan through fraudulent recruiter personas on LinkedIn and job platforms. The operators sent legitimate-looking Amazon S3-hosted coding assessments, including Node.js and React projects that concealed malicious npm packages; some lures told candidates not to use AI assistants, apparently to prevent automated review from exposing the malicious imports.
Running the supplied projects deployed the newly documented cross-platform NodeRabbit and PollCat remote-access trojans. NodeRabbit uses encrypted Azure-hosted command-and-control, performs sandbox-evasion checks, supports reconnaissance, persistence, command execution and file transfer, and has used counterfeit VS Code extensions, Git hooks, and local Outlook email collection; PollCat contacts its command server as soon as its purported React challenge loads. Kaspersky attributed the activity to Mirage Kitten with high confidence based on shared command-and-control behavior and structural overlap with its Retrograde/MiniFast malware, while noting Azure Websites and Cloudflare-fronted domains in the campaign infrastructure.

Pull IOCs and campaign context straight into your stack.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky GReAT published research describing Mirage Kitten's use of fake recruiter personas and trojanized coding challenges to deliver the newly documented NodeRabbit and PollCat cross-platform RATs. The campaign targeted fintech and aviation/aerospace organizations in Egypt, Ethiopia, and Afghanistan, and Kaspersky attributed the activity to Mirage Kitten based on technical overlaps with Retrograde/MiniFast.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.