Fake Recruitment Attack via LinkedIn by Mirage Kitten APT Group
Targeting the aviation and fintech sectors, the Mirage Kitten group is carrying out cyberattacks via fake recruitment messages and malware on LinkedIn.
The advanced persistent threat group known as Mirage Kitten is carrying out a new cyberattack campaign targeting software engineers working in the aviation and financial technology sectors. Starting with fake recruitment messages via LinkedIn, the process involves Node.js and JavaScript-based spyware.
Targets of the Global Cyber Attack
Although the main focus of the campaign includes Egypt, Ethiopia, and Afghanistan in the Middle East and Africa region, malware associated with the attacks has also been detected in countries such as Turkey, Germany, Israel, India, and Ireland.
Social Engineering and Fake Recruitment
The attackers contact software developers on LinkedIn by posing as talent acquisition specialists. Candidates are offered a technical evaluation and download a coding task hosted on Amazon cloud storage.
To create time pressure, a strict time limit is imposed on the test, and the use of AI-powered code assistants is specifically forbidden because these tools can expose the malware.
New Infrastructure Targeting Multiple Platforms
Previously relying on native programs developed in C, C++, or Go, the group has redesigned its toolset using Node.js and JavaScript. This allows Windows, macOS, and Linux systems to be targeted from a single codebase.
NodeRabbit and PollCat Spyware
Within the scope of the campaign, two new malware families were detected: a Node.js-based Remote Access Trojan named NodeRabbit and a JavaScript-based Remote Access Trojan named PollCat.
While NodeRabbit ensures persistence by installing Visual Studio Code extensions or modifying local code repositories, PollCat collects system information and scans directories to transmit data to the attackers.