Iran's Mirage Kitten APT Targets Developers with NodeRabbit, PollCat Malware
Iran-linked APT group Mirage Kitten is running a targeted cyberespionage campaign against software developers in the aviation, aerospace, and financial technology sectors, according to new research from Kaspersky. The threat actors pose as recruiters on LinkedIn and other job platforms, approaching engineers in Egypt, Ethiopia, and Afghanistan with fraudulent technical job offers from a purported major technology company. Once contact is established, candidates are asked to complete coding assessments hosted on Amazon's cloud storage service—assignments that secretly bundle previously undocumented malware families Kaspersky tracks as NodeRabbit and PollCat.
NodeRabbit is a cross-platform remote access trojan compatible with Windows, Linux, and macOS systems. First identified on a device in Afghanistan before surfacing in Egypt and Ethiopia, the RAT enables operators to enumerate host information, create or modify files, and execute arbitrary commands for full remote control of compromised endpoints. Defenders hunting for NodeRabbit beaconing activity can map suspicious listening services and outbound connections using a port scanner. PollCat functions as a secondary implant designed for persistent access and the staging of additional payloads, delivered through a similar workflow where candidates receive a six-digit access code and just one hour to complete a programming test. Both coding challenges explicitly prohibited AI coding assistants, a tactic Kaspersky researchers believe was designed to prevent automated tools from flagging the embedded malicious components before victims executed them.
Mirage Kitten—also tracked by other vendors under an alternate designation—relies heavily on legitimate cloud infrastructure to mask its command-and-control traffic. Operators abuse Microsoft Azure by registering subdomains containing the targeted organization's name, making outbound requests blend in with routine corporate network activity. Cloudflare services are similarly leveraged to obscure the true hosting locations of attacker-controlled assets. Investigators reviewing suspicious domains flagged through these campaigns can verify ownership and infrastructure details using a WHOIS lookup, while security teams should run a DNS leak test to surface unintended resolutions to attacker infrastructure. The group also pressures victims with tight deadlines—typically three hours for NodeRabbit tasks—discouraging careful analysis of the downloaded projects.
The campaign reflects a broader trend of APT actors weaponizing the recruitment pipeline against technical talent, exploiting the trust developers place in professional networking platforms and the urgency of competitive hiring processes. Organizations operating in aviation, aerospace, and fintech should treat unsolicited technical assessments with the same scrutiny as any other unsolicited software, particularly when hosted outside official corporate repositories. Security teams are advised to monitor for anomalous outbound connections to unfamiliar Azure subdomains and to audit developer endpoints for indicators of compromise related to NodeRabbit or PollCat.