Therecord.Media
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware
Article Content
The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. The first instance of NodeRabbit was detected on a system in Afghanistan, with subsequent detections in Egypt and Ethiopia. Attackers deliver these malware strains through spear-phishing emails disguised as job offers, containing trojanized coding challenge archives. The malicious archives instruct candidates to complete coding tasks while explicitly prohibiting the use of AI tools, likely to evade detection. Kaspersky has identified that these malware families represent a shift from Mirage Kitten's previous reliance on malware written in C, C++, and Go. The campaign is ongoing, and organizations in the targeted sectors are advised to remain vigilant.
Key Points: • Mirage Kitten is targeting aviation and FinTech sectors with new malware. • NodeRabbit and PollCat are cross-platform RATs delivered via trojanized job offers. • The campaign has been confirmed in Afghanistan, Egypt, and Ethiopia.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.