An Iran-linked cyberespionage group is targeting technology specialists in the aviation, aerospace and financial sectors with fake job offers designed to trick them into installing previously undocumented malware, according to new research. The group, tracked by Russian cybersecurity firm Kaspersky as Mirage Kitten, has targeted developers and other specialists in Egypt, Ethiopia and Afghanistan through LinkedIn and other job platforms. Researchers investigating the campaign uncovered two previously unknown malware families, dubbed NodeRabbit and PollCat. Both are disguised as programming assignments that victims are asked to complete as part of a purported hiring process. NodeRabbit is a remote-access trojan capable of infecting Windows, Linux and macOS systems. Once installed, it allows attackers to collect information about the victim and their computer, create or modify files and execute additional commands, giving the hackers remote access to the compromised machine. In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia. The attacks begin with fake recruiters contacting potential victims on job-search platforms with seemingly legitimate tech job offers. In one documented case, an attacker posing as a recruiter for an unnamed major technology company approached a software engineer and asked them to complete a technical assessment. The victim was directed to download a coding challenge hosted on Amazon's cloud storage service and encouraged to run the project immediately. One malicious archive found in Afghanistan contained a coding test that instructed candidates to review an application and fix its flaws within three hours. The test explicitly banned the use of AI assistants, which Kaspersky researchers said may have been intended to prevent such tools from detecting the malicious code hidden in the project. When the developer ran the coding project, the hidden malicious component executed alongside it. Researchers uncovered a similar technique involving PollCat, another previously undocumented malware family designed to provide attackers with persistent access to compromised computers and deliver additional malicious files. In that campaign, targets were given one hour to complete a programming test and needed a six-digit access code provided by the recruiter. The codes were described as single-use and valid only for a short time, putting additional pressure on candidates to open the project quickly. Kaspersky said Mirage Kitten also uses legitimate Microsoft Azure and Cloudflare infrastructure to make its activity harder to detect and track. In some cases, the hackers included the targeted organization’s name in an Azure subdomain, making communications between an infected device and their servers look more like normal corporate network traffic. Mirage Kitten, also tracked by other cybersecurity researchers as UNC1549, Smoke Sandstorm and Nimbus Manticore, is an Iranian state-backed cyberespionage group that has been active since at least 2022. The latest victims fit Mirage Kitten’s established focus on organizations in Africa and the Middle East, according to Kaspersky, with the group particularly targeting the aviation, aerospace and financial technology sectors. The tactics are also familiar. Mirage Kitten has previously posed as recruiters on LinkedIn and used fake job opportunities to target people working in sensitive industries across the region, researchers said.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.