⚠️ Region Alert: UAE/Middle East
Researchers have identified a new campaign by the Mirage Kitten APT group targeting fintech, aviation, and aerospace sectors across the Middle East and Africa. The group has evolved its arsenal to include Node.js and JavaScript-based implants, specifically the NodeRabbit and PollCat RATs. These cross-platform tools are delivered via spear-phishing on LinkedIn, where attackers pose as recruiters and provide trojanized coding challenges to unsuspecting software developers.
NodeRabbit exhibits sophisticated persistence mechanisms across Windows, Linux, and macOS, including the use of malicious VS Code extensions and Git hook injections. PollCat, a React-based RAT, shares significant structural and command-and-control similarities with the group's legacy native malware. This shift toward scripting languages allows the threat actor to maintain a single codebase for multiple operating systems while blending into legitimate developer environments and Azure-hosted infrastructure.
Top comments (0)