⚠️ Region Alert: UAE/Middle East
Mirage Kitten, an APT group focusing on the Middle East and Africa, has evolved its toolkit to include Node.js and JavaScript-based cross-platform malware dubbed NodeRabbit and PollCat. These Remote Access Trojans (RATs) are delivered through trojanized coding challenges sent via fake LinkedIn recruiter accounts targeting the fintech and aviation sectors.
The malware demonstrates sophisticated persistence mechanisms across Windows, Linux, and macOS, including the use of malicious VS Code extensions and Git hook injection. Infrastructure analysis reveals a heavy reliance on Azure and Cloudflare-backed domains to blend traffic with legitimate business communications.
Top comments (0)