An Iranian state-backed cyber espionage group known as Mirage Kitten is targeting technology professionals in the aviation, aerospace, and financial sectors using deceptive job offers. According to research by Kaspersky, these fake offers are meant to trick individuals into downloading malware disguised as coding assignments. The attacks have been reported in countries such as Egypt, Ethiopia, and Afghanistan, primarily through platforms like LinkedIn.
Kaspersky's investigation uncovered two previously unknown malware families, NodeRabbit and PollCat, which pose as programming tasks in the recruitment process. NodeRabbit functions as a remote-access trojan capable of infiltrating systems running Windows, Linux, and macOS. Once installed, it grants attackers the ability to gather information, manipulate files, and execute commands on the victim's machine. PollCat, similarly, provides persistent access and can deliver further malicious payloads.
The process begins with attackers who impersonate recruiters from major tech firms, contacting potential victims with what appear to be legitimate job offers. They direct these individuals to download a coding challenge from a cloud service, such as Amazon, and execute it immediately. In Afghanistan, for example, a developer was instructed to fix flaws in an application within three hours while being prohibited from using AI tools, possibly to avoid detection of hidden malware.
Mirage Kitten employs legitimate infrastructure like Microsoft Azure and Cloudflare to mask its activities, often using Azure subdomains that include the target organization's name. This strategy makes the malicious traffic resemble standard corporate network activity, complicating detection efforts.
This cyber espionage group, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, has been active since at least 2022. Their focus remains on the Middle East and Africa, with a particular interest in aviation and fintech sectors. The tactics of posing as recruiters and using fake job opportunities are consistent with their previous operations in the region.


