ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Iran-Linked Mirage Kitten Uses Fake LinkedIn Job Challenges to Deliver NodeRabbit and PollCat RATs

highThreat actorexploited in the wildimportance 72
What's new: First merged story (no previous summary). Consolidates two reports published 2026-09-09 (GBHackers, Cyber Security News). Adds specificity: npm package version colorized_terminal 2.1.0; challenge archive names and three-hour deadlines; PollCat persistence mechanisms (scheduled tasks, cron, LaunchAgents) and 24-vendor security-tool inventory; NodeRabbit C2 rotation and sandbox detection. Flags the…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Iran-linked Mirage Kitten (UNC1549) is targeting software engineers with fake LinkedIn recruiter coding tests that deploy two newly documented, cross-platform Node.js RATs, NodeRabbit and PollCat, against victims in aviation, aerospace and fintech in Egypt,…

Two outlets reported on 2026-09-09 a campaign in which Iran-linked Mirage Kitten (tracked as UNC1549; GBHackers adds the aliases Smoke Sandstorm and Nimbus Manticore) uses fake recruiter personas on LinkedIn to send software engineers technical hiring challenges - Front-Technical-Challenge.zip and RankChallenge-react, with three-hour deadlines - that deliver the newly documented RATs NodeRabbit and PollCat, which run on Windows, Linux and macOS. The challenges bundle malicious npm dependencies (colorized_terminal 2.1.0 per Cyber Security News; GBHackers also names pretty-log) inside bundled node_modules rather than the npm registry, evading registry trust; colorized_terminal launches NodeRabbit from a hidden cache path. NodeRabbit uses AES-256-GCM-encrypted C2 via Azure, rotates C2 servers, gathers host data, runs shell commands and detects sandboxes; its third variant persists via a fake GitHub Copilot Helper VS Code extension plus Git post-merge/post-checkout hooks. PollCat is an obfuscated JavaScript RAT that registers with C2 before OTP authentication through an attacker-controlled OTP screen, supports file transfer, hidden process execution and arbitrary JavaScript execution, inventories tools from 24 security vendors (including CrowdStrike, SentinelOne, Fortinet and Microsoft), and persists via scheduled tasks, cron and LaunchAgents (per Cyber Security News). Victims were observed in aviation, aerospace and fintech, with confirmed targets in Egypt, Ethiopia and Afghanistan. The sources name different researchers: GBHackers attributes the analysis to Kaspersky, while Cyber Security News attributes it to PolySwarm. GBHackers calls this the first documented shift from Mirage Kitten's native C, C++ and Go tooling to Node.js. Recommended defenses: verify recruiters, review dependencies and isolate hiring assessments.

  • Fake recruiter personas on LinkedIn deliver Front-Technical-Challenge.zip and RankChallenge-react coding tests with three-hour deadlines (GBHackers).
  • Malicious npm packages ship inside bundled node_modules rather than the npm registry, evading registry trust; the fake colorized_terminal package (version 2.1.0 per Cyber Security News; GBHackers also names pretty-log) launches NodeRabbit…
  • Attribution: GBHackers cites Kaspersky linking the campaign to Mirage Kitten (aka UNC1549, Smoke Sandstorm, Nimbus Manticore); Cyber Security News cites PolySwarm documenting the campaign and attributes it to Mirage Kitten (UNC1549) - the…
  • Targets: software engineers in aviation, aerospace and fintech, with confirmed victims in Egypt, Ethiopia and Afghanistan.
  • NodeRabbit: cross-platform (Windows, Linux, macOS) Node.js implant using AES-256-GCM-encrypted C2 via Azure; gathers host data, runs shell commands, detects sandboxes and rotates C2 servers.
  • NodeRabbit persistence (third variant): fake GitHub Copilot Helper VS Code extension plus Git post-merge/post-checkout hooks.
  • PollCat: obfuscated JavaScript RAT that registers with C2 before OTP authentication via an attacker-controlled OTP screen; supports file transfer, hidden process execution and arbitrary JavaScript execution.
  • PollCat inventories tools from 24 security vendors, including CrowdStrike, SentinelOne, Fortinet and Microsoft; persists via scheduled tasks, cron and LaunchAgents (per Cyber Security News).

Coverage timeline

  1. · 7d ago
    GBHackers· 72
    Iran-Linked Hackers Use Fake LinkedIn Job Offers to Deploy NodeRabbit and PollCat RATs

    Iran-linked Mirage Kitten targets software engineers with fake LinkedIn recruiter coding tests deploying new NodeRabbit and PollCat RATs.