Iran-Linked Mirage Kitten Deploys Fake Coding Challenges to Slip Malware Past Recruiters
Cybersecurity investigators have identified a novel recruitment ploy used by the Iran-affiliated threat group known as Mirage Kitten. The actors posted counterfeit coding assessments on LinkedIn, presenting them as legitimate job screenings. Unwitting participants who completed the tests inadvertently downloaded the malicious payloads NodeRabbit and PollCat, giving the group a covert entry point into target networks.
The operation leverages the trust placed in professional networking platforms, where job seekers often engage with technical challenges to showcase their skills. By embedding malicious code within the test files, Mirage Kitten bypasses traditional security checks that focus on external email attachments or drive‑by downloads. The approach also sidesteps many automated sandbox environments that flag known malware signatures.
NodeRabbit, a Node.js‑based backdoor, enables remote command execution and data exfiltration, while PollCat functions as a credential‑stealing tool that harvests login information from compromised systems. Both have been observed in previous campaigns attributed to Iranian cyber‑espionage units, suggesting a continuity of tool development within the group’s arsenal.
In an additional twist, the attackers reportedly prohibited the use of artificial‑intelligence‑driven analysis tools on the test files. By instructing candidates not to employ AI‑assisted code reviewers, the group aimed to prevent early detection by modern static‑analysis platforms that could flag the embedded malicious routines.
Security experts say the scheme underscores a growing trend of threat actors exploiting recruitment pipelines to deliver malware. Similar tactics have been recorded in other state‑aligned groups, where fake job offers or conference invitations serve as vectors for initial compromise. The Mirage Kitten campaign highlights the need for organizations to scrutinize any unsolicited technical assessments, especially those arriving through personal networking channels.
Defenders are advised to implement strict verification of external coding challenges, employ sandboxing for any downloaded scripts, and educate potential candidates about the risks of executing unknown code. As the line between legitimate professional outreach and cyber‑espionage blurs, vigilance across both HR and IT departments will be essential to thwart such covert intrusion methods.
Comments (0)
Be the first to comment.
Join the discussion