$ techbeacon▋
Darkweb

Iran‑linked Mirage Kitten Lures Developers with Bogus Coding Tests to Install New RATs

Iran‑linked Mirage Kitten Lures Developers with Bogus Coding Tests to Install New RATs

Cyber‑security researchers have uncovered a new recruitment‑fraud campaign run by the Iran‑affiliated threat group known as Mirage Kitten. The actors pose as recruiters on professional networks such as LinkedIn, offering fake coding challenges that appear to be part of legitimate hiring processes. When candidates download the supplied test files, the payload silently installs two previously unknown cross‑platform remote‑access trojans, dubbed NodeRabbit and PollCat.

The operation targets software developers and other technical professionals who are accustomed to completing online assessments as part of job applications. By embedding the malicious code within seemingly innocuous test scripts, the attackers exploit the trust placed in recruitment communications. Once executed, the trojans grant the adversaries full control over the victim’s machine, enabling data exfiltration, credential theft, and further lateral movement within corporate networks.

NodeRabbit and PollCat are designed to run on multiple operating systems, reflecting Mirage Kitten’s intent to reach a broad audience. Early analysis shows the malware can establish encrypted command‑and‑control channels, download additional modules, and persist across reboots. Their cross‑platform nature also complicates detection, as traditional endpoint tools may not flag the code when it masquerades as legitimate development utilities.

Security firms note that the use of recruiter impersonation is not new, but the integration of full‑featured remote‑access tools marks an escalation in the threat’s sophistication. By coupling social engineering with advanced malware, Mirage Kitten blurs the line between conventional phishing and supply‑chain compromise. The campaign underscores the importance of verifying the authenticity of job‑related communications, especially when they involve the download of executable content.

Experts recommend that developers and hiring teams adopt multi‑factor verification for recruitment outreach, avoid downloading files from unsolicited sources, and employ sandboxing or reputable antivirus solutions to scan any assessment materials. As the investigation continues, analysts will monitor for additional variants of NodeRabbit and PollCat, as well as any signs that the group is expanding its lure to other technical domains.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related