Iranian hackers target devs via fake coding tests
Two previously undocumented malware families (NodeRabbit and PollCat) reach developers under the cover of job interviews, and the tests are explicitly timed to short-circuit scrutiny.
TL;DR
An Iran-linked group tracked as Mirage Kitten is using fake job offers on LinkedIn and other platforms to distribute two new malware families, NodeRabbit and PollCat, to developers and specialists in aviation, aerospace, and financial technology. Targets identified so far are in Egypt, Ethiopia, and Afghanistan. The malware is disguised as coding assessments (one hosted on Amazon cloud storage) and the process pressures candidates to run the malicious project immediately, with tight time limits and single-use access codes that expire quickly.
Kaspersky published the findings Tuesday, identifying the actor as Mirage Kitten (also tracked elsewhere as UNC1549, Smoke Sandstorm, and Nimbus Manticore) and attributing the campaign to Iranian state-backed espionage. The group has been active since at least 2022, with a consistent focus on the Middle East and Africa.
The ruse is straightforward: a fake recruiter for a major tech company contacts a software engineer, offers a role, and sends a coding challenge. One documented case involved a project hosted on Amazon's cloud storage service. The candidate was told to download and run it immediately. A separate instance in Afghanistan included a three-hour limit and an explicit ban on AI assistants, a restriction Kaspersky researchers suggest was meant to prevent AI tools from flagging the malicious code hidden in the project.
NodeRabbit is a remote-access trojan that can infect Windows, Linux, and macOS systems. It collects system information, creates or modifies files, and executes commands. PollCat is a backdoor that provides persistent access and delivers additional payloads. In the PollCat campaign, targets were given one hour and a six-digit single-use access code from the recruiter to complete the test, adding time pressure to open and run the project.
Kaspersky first found NodeRabbit on a system in Afghanistan and later on machines in Egypt and Ethiopia. The group also uses legitimate Microsoft Azure and Cloudflare infrastructure to blend its traffic, in some cases embedding the target organization's name in Azure subdomains so that command-and-control communications resemble normal corporate traffic.
The fake-recruiter technique is a known play in state-sponsored espionage. It's been heavily associated with North Korean operations, but Mirage Kitten has used it before as well. ClearSky documented a related Iranian campaign in 2023 that impersonated recruiters on LinkedIn to target aerospace with SnailResin and SlugResin malware. Mandiant had previously flagged Iranian fake-recruiter profiles aimed at the same sectors in Israel, the UAE, and possibly Turkey, India, and Albania.
The sectors here (aviation, aerospace, financial technology) and the geography (Africa and the Middle East) fit Mirage Kitten's established pattern. What's new is the malware itself, and the deliberate friction built into the hiring sham: short clocks, expiring codes, and a prohibition on the one tool that might catch the payload.
Published ·Deep Fathom