README instructions and challenge overview included in the trojanized React coding project
At a Glance
| Actor or group | Allegedly Mirage Kitten (UNC1549, Smoke Sandstorm) |
| Activity type | Cyberespionage and remote access trojan deployment |
| Targets or victims | Aviation, aerospace, and fintech developers |
| Scale | Multiple targeted victims across several countries |
| Law-enforcement status | No announced arrests; active campaign |
| Sources | Kaspersky Labs |
TL;DR
Suspected threat actors are using a Mirage Kitten malware campaign to target software engineers. First, they hide malware inside fake coding tests sent via professional networking sites. Ultimately, these fake tests secretly install new remote access trojans called NodeRabbit and PollCat.
What Happened
The Recruitment Setup
Recently, fake recruiters contacted job seekers on LinkedIn with seemingly legitimate tech job offers. Specifically, the attackers targeted software developers in critical industries. Then, they invited candidates to complete a technical assessment. These attackers often posed as talent acquisition specialists at major technology companies. They used the natural stress of the hiring process to manipulate victims.
The Coding Challenge Trap
Next, the targets received a ZIP archive file. The file contained a coding challenge hosted on a legitimate Amazon S3 bucket. This setup appeared completely normal to most job applicants. There, the attackers instructed developers to fix frontend bugs.
Importantly, they explicitly banned the use of AI assistants. They also imposed a strict three-hour time limit. Consequently, this restriction likely aimed to stop AI tools from catching the malicious code. A quick code review by an AI would have flagged the trojanized packages instantly.
The Dual Backdoor Infection
However, the archive included hidden threats. In fact, the first line of a backend file imported a trojanized package. This specific package was named colorized_terminal. Subsequently, this package quietly launched the new Mirage Kitten malware in the background.
The malware then generated a unique agent identifier from available host information. It calculated hashes of the hostname, username, and operating system version. Then, it established persistence mechanisms specific to the victim’s operating system. On Windows, it hid itself as an Edge update process. On macOS, it created persistent launch agents.
Simultaneously, researchers discovered another remote access trojan named PollCat. Meanwhile, attackers distributed PollCat through a separate React coding project. They pressured candidates with a one-hour time limit and expiring access codes. The fake application even used capture-the-flag terminology to look authentic.
Interestingly, PollCat started independently of the authentication process. It began polling for commands before the user even entered a code. Ultimately, both NodeRabbit and PollCat operate natively across Windows, Linux, and macOS environments.
Kaspersky Labs detailed these findings in a recent report. The report stated, “NodeRabbit and PollCat represent the first publicly documented use of Node.js and JavaScript-based malware by this APT group.” Furthermore, the researchers noted a major strategic change. They noted, “the shift to cross-platform scripting gives the operators a single codebase that runs on Windows, Linux, and macOS.”
Who Is Behind It
Attribution to Mirage Kitten
Kaspersky attributes this activity to Mirage Kitten with a high degree of confidence. Also, security researchers track this Iranian state-backed group as UNC1549 and Smoke Sandstorm. Historically, the group used native malware written in C, C++, and Go. Therefore, this recent shift shows a change in their tactics. Nevertheless, the delivery mechanism matches their historical tradecraft. They still use fake recruiter personas on professional networking platforms.
Tactical Infrastructure Shifts
Additionally, the attackers used Microsoft Azure subdomains for their command servers. This tactic helps the malicious traffic blend into normal business activity. In addition, the malware delegates corporate proxy authentication to blend in further. It actively hunts for HTTP proxy environment variables and internet settings. All of this strongly aligns with suspected Mirage Kitten behavior.
Impact or Scale
High-Value Targets
The Mirage Kitten malware successfully infected systems in Afghanistan, Egypt, and Ethiopia. Besides that, security platforms detected trojanized project submissions from India, Germany, and Ireland. Overall, the campaign heavily targeted the aviation, aerospace, and fintech sectors. These are high-value industries.
Once installed, the malware grants attackers deep access to developer workstations. Attackers can execute commands, steal files, and maintain persistent access. They can also plant fake code extensions to remain hidden. One variant even injected a malicious launcher directly into Git repositories. Consequently, a single compromised developer account can expose massive amounts of corporate data. A successful intrusion could lead to severe intellectual property theft.
What Comes Next and How to Stay Protected
Ongoing Social Engineering
The group will likely continue targeting developers using social engineering. They exploit the pressure of technical job interviews. Clearly, this tactic proves highly successful. Developers often lower their guard when presented with a lucrative job opportunity.
Defensive Measures
To begin with, readers can stay protected by exercising caution online. Always verify the identity of recruiters reaching out on LinkedIn. Do not download and run unsolicited ZIP files from unverified sources. Moreover, inspect coding challenge projects in isolated virtual machines. Never execute external code on your primary workstation. Finally, developers should remain skeptical of tests that ban standard security analysis tools. Organizations must train employees to recognize these social engineering tactics.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!