Iran-Linked Cyberespionage Group Leverages Fake Job Offers to Deploy New Malware
An Iranian state-backed cyberespionage group, known as **Mirage Kitten**, is actively targeting technology specialists in critical sectors with sophisticated fake job offers. These campaigns trick victims into installing two previously unknown malware families, **NodeRabbit** and **PollCat**, designed for persistent access and data exfiltration across multiple operating systems.
# Iran-Linked Cyberespionage Group Leverages Fake Job Offers to Deploy New Malware
An Iran-linked cyberespionage group, tracked by **Kaspersky** as **Mirage Kitten**, is employing elaborate fake job offers to compromise technology specialists in the aviation, aerospace, and financial sectors. The campaign, which has targeted individuals in Egypt, Ethiopia, and Afghanistan, leverages platforms like **LinkedIn** to deliver previously undocumented malware.
## Uncovering New Malware: NodeRabbit and PollCat
Researchers investigating the campaign have identified two new malware families: **NodeRabbit** and **PollCat**. Both are disguised as programming assignments, presented as part of a purported hiring process.
**NodeRabbit** is a potent remote-access trojan (RAT) capable of infecting **Windows**, **Linux**, and **macOS** systems. Once installed, it grants attackers extensive control, allowing them to collect system information, manipulate files, and execute arbitrary commands, effectively giving them remote access to the compromised machine. **Kaspersky** first detected **NodeRabbit** in Afghanistan, with variants later appearing in Egypt and Ethiopia.
## The Deceptive Recruitment Tactic
The attacks commence with seemingly legitimate job offers from fake recruiters contacting potential victims on job-search platforms. In one documented instance, an attacker impersonating a recruiter for a major technology company approached a software engineer. The target was directed to download a coding challenge hosted on **Amazon**'s cloud storage service and encouraged to run the project immediately.
One malicious archive discovered in Afghanistan contained a coding test instructing candidates to review and fix flaws in an application within a tight three-hour deadline. Notably, the test explicitly prohibited the use of AI assistants, a tactic **Kaspersky** researchers believe was intended to prevent AI tools from detecting the malicious code embedded within the project. When the developer executed the coding project, the hidden malicious component was simultaneously activated.
A similar technique was observed with **PollCat**, another newly identified malware family. **PollCat** is designed to provide attackers with persistent access to compromised computers and facilitate the delivery of additional malicious files. In these campaigns, targets were given a one-hour deadline for a programming test and required a single-use, time-sensitive six-digit access code from the recruiter, adding pressure to quickly open the malicious project.
## Evading Detection with Legitimate Infrastructure
**Mirage Kitten** employs legitimate infrastructure from **Microsoft Azure** and **Cloudflare** to mask its activities, making detection and tracking more challenging. In some cases, the threat actors incorporated the targeted organizationβs name into an Azure subdomain, making communications between an infected device and their command-and-control servers appear as normal corporate network traffic.
## Mirage Kitten: A Persistent Threat
**Mirage Kitten**, also tracked by other cybersecurity researchers as **UNC1549**, **Smoke Sandstorm**, and **Nimbus Manticore**, is an Iranian state-backed cyberespionage group active since at least 2022. Their latest victims align with the group's established focus on organizations in Africa and the Middle East, particularly within the aviation, aerospace, and financial technology sectors.
The tactics employed are consistent with **Mirage Kitten**'s previous operations. The group has a history of impersonating recruiters on **LinkedIn** and using fake job opportunities to target individuals in sensitive industries across the region.