Recent investigations into the activities of the cyber espionage group known as Mirage Kitten have revealed the emergence of two new malware families: NodeRabbit and PollCat. These represent a significant shift in the group’s tactics, as they mark the first documented use of Node.js and JavaScript-based malware by this advanced persistent threat (APT) group. The initial discovery of NodeRabbit occurred on a system in Afghanistan, with subsequent variants identified in Egypt and Ethiopia. This development is detailed in a report by Kaspersky, which highlights the evolving nature of cyber threats in the region.
NodeRabbit is a cross-platform remote access trojan (RAT) designed to target Windows, Linux, and macOS systems. Its distribution typically occurs through spear-phishing messages on platforms like LinkedIn, where attackers lure potential victims with trojanized coding challenge archives. This method exploits the job application process, making it particularly insidious as it preys on individuals seeking employment in the tech sector.
In parallel, the researchers also uncovered PollCat, another RAT that, like NodeRabbit, is distributed via similar trojanized coding challenges but is built using obfuscated JavaScript. This dual approach of using both Node.js and JavaScript reflects a strategic pivot for Mirage Kitten, which has historically relied on native malware written in languages such as C, C++, and Go, often deploying it through DLL search-order hijacking.
Technical Insights into NodeRabbit
The NodeRabbit malware operates by embedding itself within seemingly legitimate software development projects. For instance, one of the identified samples was hidden in an archive labeled as a coding challenge, which included a README file instructing candidates to review and fix defects in a frontend application. This README cleverly directed attention away from the malicious modifications made to the project’s source files.
Upon execution, NodeRabbit generates a unique agent identifier based on various host parameters and establishes a TCP listener to facilitate communication with its command-and-control (C2) servers. The malware employs a sophisticated persistence mechanism tailored to each operating system, ensuring it remains active even after system reboots. For example, on Windows, it modifies registry keys to execute its payload at startup, while on Linux and macOS, it utilizes cron jobs and launch agents, respectively.
PollCat’s Operation and Delivery Mechanism
PollCat operates similarly, leveraging the guise of a coding challenge to initiate its infection chain. The malware begins its execution process independently of any authentication mechanisms, allowing it to establish a connection with its C2 infrastructure before the user even enters an access code. This design choice enhances its stealth and effectiveness.
Both NodeRabbit and PollCat utilize Azure-hosted domains for their C2 communications, blending their traffic with legitimate organizational activities. This tactic complicates detection efforts, as the malware can masquerade as regular business traffic. The use of such infrastructure is consistent with Mirage Kitten’s historical patterns, which have included leveraging legitimate third-party services for malware distribution.
Victimology and Attribution
The telemetry data indicates that the primary targets of these malware families are entities within the fintech and aviation sectors across the Middle East and Africa, particularly in countries like Egypt, Ethiopia, and Afghanistan. This aligns with Mirage Kitten’s known focus on critical sectors in these regions.
Attribution to Mirage Kitten is supported by several factors, including structural similarities between the new malware and previously identified tools used by the group, as well as their established operational patterns. The group’s continued evolution in tactics and tools underscores the persistent threat they pose to organizations in targeted sectors.
As the cybersecurity landscape continues to evolve, the emergence of NodeRabbit and PollCat serves as a reminder of the need for vigilance and robust security measures, particularly in environments where software development and job recruitment intersect. The ongoing monitoring of Mirage Kitten’s activities will be crucial in understanding and mitigating the risks associated with these new malware families.
For further details on this research, you can refer to the full report by Kaspersky here.
Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.



