DEV Community

Mark0
Mark0

Posted on

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

⚠️ Region Alert: UAE/Middle East

Mirage Kitten, an APT group focusing on the Middle East and Africa, has evolved its toolkit to include Node.js and JavaScript-based cross-platform malware dubbed NodeRabbit and PollCat. These Remote Access Trojans (RATs) are delivered through trojanized coding challenges sent via fake LinkedIn recruiter accounts targeting the fintech and aviation sectors.

The malware demonstrates sophisticated persistence mechanisms across Windows, Linux, and macOS, including the use of malicious VS Code extensions and Git hook injection. Infrastructure analysis reveals a heavy reliance on Azure and Cloudflare-backed domains to blend traffic with legitimate business communications.


Read Full Article

Top comments (0)