An Iran-linked cyberespionage group is targeting developers and technology specialists in aviation, aerospace and financial technology organizations with fake recruitment campaigns designed to trick victims into executing malicious coding projects.
The threat group, tracked as Mirage Kitten, is also known as UNC1549, Smoke Sandstorm and Nimbus Manticore. Kaspersky researchers attributed the latest activity to Mirage Kitten with a high degree of confidence and identified victims in Egypt, Ethiopia and Afghanistan.
The campaign introduces two previously undocumented malware families, NodeRabbit and PollCat, both delivered through trojanized programming assessments presented as legitimate hiring exercises.
NodeRabbit is a cross-platform remote-access trojan built with Node.js and capable of operating on Windows, Linux and macOS. PollCat is also cross-platform but is written in obfuscated JavaScript. Kaspersky said the malware represents the first publicly documented use of Node.js- and JavaScript-based implants by Mirage Kitten, marking a shift from the group’s previous reliance on native malware written in C, C++ and Go.
The attacks begin with fake recruiter accounts contacting prospective targets through LinkedIn and other job-search platforms.
Targets are offered what appears to be a legitimate software engineering position and are then instructed to complete a technical assessment.
In one documented infection chain, the target received a coding challenge hosted in an Amazon S3 bucket. The archive contained a software-development project built with Express, React and Vite and instructed the candidate to identify and repair defects in the application.
The instructions specifically told the candidate that one server-side file did not need to be reviewed.
That file contained a malicious import pointing to a trojanized Node.js package bundled inside the archive. When the developer launched the project, the package silently executed the NodeRabbit implant as a detached background process.
The coding challenge also imposed a three-hour time limit and explicitly prohibited use of AI assistants.
Kaspersky assessed that an AI-assisted code review could have exposed the suspicious package import, making the restriction potentially useful to the attackers by reducing the chance that automated analysis would identify the malicious component before execution.
Once active, NodeRabbit can collect detailed information from the compromised system, execute shell commands, enumerate processes and network settings, create and delete files, read stored data, write new data and execute additional Node.js scripts.
The first identified variant supported 11 remote commands, including process execution, directory listing, file retrieval, file modification and system reconnaissance.
Later NodeRabbit variants became substantially more capable.
A third variant identified on a system in Ethiopia expanded the command set to 23 functions and added capabilities for harvesting Outlook account addresses from OST and PST artifacts, scanning development directories for Git repositories, injecting persistence mechanisms into Git hooks and establishing persistence through Visual Studio Code.
One persistence mechanism creates a malicious extension displayed as “GitHub Copilot Helper” and attempts to launch the malware whenever Visual Studio Code starts.
The malware can also inject launch instructions into Git repository hooks, allowing a future developer action such as a checkout or merge to restart the malicious payload.
Those mechanisms create particular risk inside development environments because compromised workstations may contain source code, project credentials, API keys, cloud tokens, internal repositories and access to production infrastructure.
The same investigation uncovered PollCat, a second malware family delivered through another fake programming exercise.
That campaign used a React-based coding challenge with a one-hour completion window and a six-digit access code supplied by the fake recruiter.
The instructions described the codes as single-use and short-lived, adding pressure for candidates to open and run the project quickly.
The authentication process itself was not required for infection. Kaspersky found that PollCat could begin registering with attacker-controlled infrastructure and polling for commands while the application was still loading, before the victim entered the access code.
PollCat supports file movement, process execution, shell commands, directory enumeration, process termination, archive creation, file transfers and arbitrary JavaScript execution.
It can also collect information about running processes and enumerate files and folders in application, user, Outlook and security-software-related directories on the victim system.
The malware communicates with command-and-control infrastructure hosted across legitimate cloud services and attacker-controlled domains.
Mirage Kitten continues to use Microsoft Azure Websites and Cloudflare-backed infrastructure to obscure malicious communications among normal enterprise traffic.
Kaspersky found instances where attackers incorporated the targeted organization’s name into Azure subdomains, making command-and-control traffic appear more consistent with ordinary corporate activity.
That tactic can complicate detection because defenders cannot assume that traffic involving a trusted cloud platform is automatically benign.
The group has used similar tradecraft before.
Google’s Mandiant previously documented UNC1549 targeting aerospace, aviation and defense organizations through phishing campaigns, fake recruitment sites and legitimate cloud infrastructure. Mandiant assessed the activity as Iran-nexus espionage and linked the group’s operations to targeting patterns involving the aerospace and defense ecosystem across the Middle East.
Kaspersky’s latest victim telemetry shows infections affecting fintech, aviation and aerospace organizations in Egypt, Ethiopia and Afghanistan.
Researchers also identified submissions of trojanized NodeRabbit and PollCat archives from India, Türkiye, Israel, Iraq, Germany and Ireland, although those submissions do not by themselves confirm successful compromises in each country.
The campaign demonstrates why recruitment activity has become an attractive initial-access technique against technical personnel.
Developers routinely download source-code archives, clone repositories, install dependencies and execute unfamiliar projects as part of legitimate hiring assessments.
Attackers can exploit that workflow by placing malicious components inside otherwise credible software projects rather than relying on traditional executable attachments that may trigger immediate suspicion.
The cross-platform design of NodeRabbit and PollCat expands the potential reach further.
A single malicious codebase can now target developers regardless of whether they use Windows, Linux or macOS, reducing the need for the operators to build separate malware families for each operating system.
Organizations in aviation, aerospace, fintech and other sensitive sectors should treat unsolicited coding assessments as potential attack vectors, particularly when recruiters pressure candidates to execute downloaded projects quickly or discourage independent code review.
Technical personnel should inspect package dependencies, startup scripts, repository hooks, Visual Studio Code extensions and unfamiliar Node.js modules before running external projects.
Security teams should also monitor developer endpoints for unexpected scheduled tasks, new LaunchAgents, cron entries, suspicious Git hooks, unauthorized VS Code extensions and unusual outbound communications to cloud-hosted infrastructure.
Mirage Kitten’s latest campaign shows a clear evolution in tooling without abandoning the group’s established reliance on targeted social engineering.
The lure remains familiar: a credible recruiter, a plausible job opening and a technical challenge.
The payload has changed.
NodeRabbit and PollCat now give the operators cross-platform access designed to blend directly into the workflows of the developers and specialists they are trying to compromise.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



