Mirage Kitten Deploys Node Rabbit and PollCat RATs via Fake Coding Challenges

Share:

Kaspersky reports that the espionage actor it tracks as Mirage Kitten has begun using its first Node.js
and JavaScript malware, two cross-platform remote access trojans named NodeRabbit and PollCat
that run on Windows, Linux and macOS. The group delivers them through fake recruiter personas on
LinkedIn and job platforms, sending targets a trojanized coding challenge, hosted on Amazon S3, as a
technical assessment; when the developer runs the project, a malicious npm package bundled inside it
silently launches the implant. Once active, the RATs give operators full control of the machine,
harvesting Outlook email, running commands and stealing files, and they persist through developer
tools such as a fake VS Code extension and injected Git hooks. Kaspersky observed victims in fintech,
aviation and aerospace across the Middle East and Africa, and organisations whose engineers accept
external coding assessments should treat this recruiter lure as a live threat to developer workstations.

1. Campaign Overview

Kaspersky reports that the espionage actor it tracks as Mirage Kitten has adopted its first Node.js and JavaScript malware: two cross-platform remote access trojans, NodeRabbit and PollCat, that run on Windows, Linux and macOS. This is a shift from the group’s usual native C, C++ and Go tooling deployed through DLL search-order hijacking. Delivery, however, follows its established playbook: fake recruiter personas on LinkedIn and job platforms send a trojanized coding challenge, hosted on Amazon S3, as a technical assessment. When the developer runs the project, a bundled malicious npm package silently launches the implant. Kaspersky detects the threat as Trojan.JS.MirageKitten.*.

2. Targeting

Kaspersky observed victims in the fintech, aviation and aerospace sectors across the Middle East and Africa, specifically in Egypt, Ethiopia and Afghanistan, consistent with Mirage Kitten’s known regional focus. The lure deliberately targets software developers and engineers, whose workstations hold source code, cloud and repository credentials, and mailbox access. Trojanized-project submissions were also seen from India, Turkiye, Israel, Iraq, Germany and Ireland. Any organisation whose engineers accept external coding assessments, particularly in aviation, aerospace and financial services, should treat this recruiter-lure delivery as a live risk to developer endpoints.

3. Attack Details

The delivery relies on social engineering of developers rather than any software vulnerability.

  • Initial Access RECRUITER LURE: A fake recruiter contacts a developer on LinkedIn or a job platform and sends a time-limited coding assessment as a ZIP hosted on Amazon S3, pressuring the target to download and run it immediately.
  • Execution TROJANIZED NPM PACKAGE: The archive bundles a malicious npm package (colorized_terminal or pretty-log, pinned to v2.1.0) directly in node_modules; importing it silently launches the implant from node_modules/.cache as a detached background process.
  • Command & Control AZURE AND CLOUDFLARE: The RATs beacon over HTTPS to Azure Websites and Cloudflare-backed domains, sometimes echoing the victim organisation’s name to blend into normal business traffic, with encrypted or obfuscated request bodies.
  • Collection CREDENTIALS AND MAIL: Operators run shell commands, enumerate the host, harvest Outlook OST and PST email artifacts, and read and exfiltrate files from the developer’s machine.
  • Persistence DEVELOPER WORKFLOWS: Beyond Run keys, scheduled tasks, cron and LaunchAgents masquerading as Microsoft Edge Update or Intel DSA, the actor installs a fake GitHub Copilot Helper VS Code extension and injects Git hooks so routine developer actions relaunch the malware.
  • Evasion BLENDING AND ANTI-ANALYSIS: Later variants check for analysis environments before running, emit benign decoy web requests, patch node.exe to hide its console window, and tunnel C2 through corporate proxies using the victim’s own credentials.

4. Malware & Capabilities

Both implants are full-featured, cross-platform RATs that blend into developer machines.

  • NodeRabbit (Node.js RAT): Cross-platform, with AES-256-GCM-encrypted C2 and three variants that grow from 11 to 23 commands, including shell execution, file operations, process control, network enumeration, Outlook email harvesting and arbitrary Node/JS execution. It masquerades as Microsoft Edge Update or Intel Driver & Support Assistant for persistence.
  • PollCat (JavaScript RAT): Cross-platform, starts during application load before any access code is entered, and declares about 22 commands (shell, file operations, ZIP, RUNDLL, EVAL_JS). Its system inventory scans for 24 named security-vendor folders, and its C2 handshake unusually treats an HTTP 400 response as a successful registration.
  • Developer-workflow persistence: A fake ‘GitHub Copilot Helper’ VS Code extension (activating on StartupFinished, with Workspace Trust disabled) and Git-hook injection into post-merge and post-checkout hooks (marker ‘# shepherd persist’) so ordinary developer actions relaunch the payload.
  • Evasion and proxy-aware C2 Sandbox and analysis-environment checks, benign decoy requests to google.com, microsoft.com and cloudflare.com before exit, node.exe patched from console to GUI to hide its window, and C2 tunnelled through corporate proxies using the victim’s NTLM/Negotiate credentials via curl.

5. Indicators of Compromise (IOCs)

  • https://www.virustotal.com/gui/collection/7ae8fd2e2a05069b8c95bd2ac558c19abdd79c5d2671a68da4d2b2e36ffc5d47/iocs

6. Recommendations

  • Warn engineering and developer staff about the fake-recruiter coding-challenge lure: unsolicited ‘technical assessments’ delivered as archives from cloud links, with time pressure and a ‘no AI assistant’ rule, should be treated as hostile, and untrusted project archives must never be run on a work machine.
  • Run any untrusted or candidate code only in isolated, monitored sandboxes or virtual machines with no access to corporate credentials, mail or network, and make this a standard policy for coding assessments.
  • Detect the delivery mechanic: hunt for npm projects that bundle packages directly in node_modules (for example colorized_terminal or pretty-log v2.1.0) instead of installing from the registry, node processes spawning detached background children from node_modules/.cache, and node.exe copied or renamed (nodew.exe, IntelDSA.exe) with its PE subsystem patched from console to GUI.
  • Hunt persistence and developer-workflow abuse: Run keys, scheduled tasks, cron entries or LaunchAgents masquerading as Microsoft Edge Update, Intel DSA or NetSync; fake ‘GitHub Copilot Helper’ VS Code extensions and disabled Workspace Trust; and injected Git hooks (post-merge/post-checkout containing the ‘# shepherd-persist’ marker).
  • Monitor C2 behaviour from developer workstations: outbound HTTPS to .azurewebsites[.]net and Cloudflare-backed domains (especially subdomains echoing your organisation’s name), the API paths /api/rabbit/, /sdk/v2/, /beacon and /gate/, and Outlook OST/PST access by node processes, and alert on Kaspersky’s Trojan.JS.MirageKitten.* detections.
  • Block the IOCs at their respective controls, https://www.virustotal.com/gui/collection/7ae8fd2e2a05069b8c95bd2ac558c19abdd79c5d2671a68da4d2b2e36ffc5d47/iocs

7. Sources

  • https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244
  • https://www.virustotal.com/gui/collection/7ae8fd2e2a05069b8c95bd2ac558c19abdd79c5d2671a68da4d2b2e36ffc5d47/iocs

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert