EXECUTIVE SUMMARY:
Mirage Kitten has been observed conducting targeted cyberespionage activity against aviation, aerospace, and FinTech organizations across the Middle East and Africa using two previously undocumented cross-platform remote access trojans (RATs), NodeRabbit and PollCat. The campaign primarily targets software developers through fake recruitment approaches and job-related technical assessments. Victims are encouraged to download trojanized coding challenge projects hosted on legitimate cloud infrastructure, allowing the malware to blend into normal developer activity. NodeRabbit is implemented in Node.js, while PollCat is written in obfuscated JavaScript, representing a shift toward script-based malware capable of operating across Windows, Linux, and macOS environments.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Mirage Kitten has been observed conducting targeted cyberespionage activity against aviation, aerospace, and FinTech organizations across the Middle East and Africa using two previously undocumented cross-platform remote access trojans (RATs), NodeRabbit and PollCat. The campaign primarily targets software developers through fake recruitment approaches and job-related technical assessments. Victims are encouraged to download trojanized coding challenge projects hosted on legitimate cloud infrastructure, allowing the malware to blend into normal developer activity. NodeRabbit is implemented in Node.js, while PollCat is written in obfuscated JavaScript, representing a shift toward script-based malware capable of operating across Windows, Linux, and macOS environments.[emaillocker id="1283"]
The attack begins with fake recruiter profiles contacting targeted professionals through job-search platforms and directing them to download coding-assessment archives hosted on legitimate cloud infrastructure. The projects contain malicious npm packages, including colorized_terminal and pretty-log, which execute NodeRabbit in the background when the application is launched. NodeRabbit establishes persistence through Windows Registry Run keys, Linux cron jobs, and macOS LaunchAgents, while communicating with Azure-hosted command-and-control infrastructure. It can collect host information, enumerate processes and directories, execute shell commands, read, write, and delete files, and create directories. PollCat uses a similar recruitment-themed delivery mechanism and maintains persistence through scheduled tasks, cron entries, and macOS LaunchAgents. Its command set supports shell execution, process enumeration, file transfer, directory operations, DLL loading, hidden process execution, JavaScript execution, system inventory collection, and configurable C2 polling. The malware also searches for indicators associated with security products and sends collected system information to its C2 infrastructure.
The campaign highlights an evolution in Mirage Kittens tooling and delivery methods, combining recruitment-themed lures with malicious developer projects to compromise personnel working in high-value industries. The use of Node.js and JavaScript provides cross-platform capabilities while allowing the malware to blend into legitimate development environments and workflows. The incorporation of malicious VS Code extensions, Git hooks, encrypted C2 communication, proxy handling, anti-analysis checks, and cloud-hosted infrastructure further strengthens persistence and evasion. Organizations in targeted sectors should therefore monitor suspicious coding assignments, unexpected package installations, unauthorized developer-tool extensions, abnormal Node.js activity, Git hook modifications, and outbound connections from development environments to untrusted infrastructure.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Stealth | T1027.002 | Obfuscated Files or Information | Software Packing |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
REFERENCES:
The following reports contain further technical details:
https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
[/emaillocker]