logo

Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs

ID: bab8614f-bb1f-5606-bde6-1b5f5d59457f

STIX ID: report--bab8614f-bb1f-5606-bde6-1b5f5d59457f

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-09-01

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

Kaspersky documents an Iran-linked Mirage Kitten campaign that targets software developers with fake recruitment coding challenges containing trojanized Node.js projects; these deliver two cross‑platform RATs — NodeRabbit and PollCat — which provide persistence, host enumeration, remote command execution, file transfer, and Azure-hosted C2 communications. The attackers abuse developer workflows (npm packages, VS Code extensions, Git hooks), have observed victims in fintech, aviation, and aerospace across the Middle East and Africa, and published multiple domains/IOCs; defenders are advised to treat unsolicited assessments as untrusted, inspect dependencies, isolate execution, and monitor for unexpected Node.js processes and new persistence mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.