Mirage Kitten Deploys Node.js and JavaScript RATs Through Fake Job Challenges

· Original article ↗

Summary

Kaspersky details Mirage Kitten’s use of NodeRabbit and PollCat, cross-platform RATs delivered in trojanized coding challenges to targets in the Middle East and Africa.

Key points

  • Fake recruiter accounts lure developers with coding assessments hosted in ZIP archives, including projects hosted on Amazon S3.
  • NodeRabbit is a Node.js RAT targeting Windows, Linux, and macOS; PollCat is a separate RAT written in obfuscated JavaScript.
  • Both malware families establish persistence across operating systems and support remote commands, including file access and process execution.
  • A newer NodeRabbit variant can install a fake VS Code extension and inject launchers into Git hooks to persist through developer workflows.
  • PollCat can start C2 communications before the user completes the lure’s OTP login; successful authentication can trigger another instance and persistence.
  • The operators use Azure-hosted and other domains for C2, with some traffic designed to blend into legitimate network activity.
  • Kaspersky attributes the activity to Mirage Kitten and reports telemetry identifying victims in fintech, aviation, and aerospace sectors in Afghanistan, Egypt, and Ethiopia.

Article Details

Attack Vectors
  • Fake recruiter accounts contact targets on job-search platforms and direct them to trojanized coding-challenge archives hosted on Amazon S3.
  • Running the challenge project imports a bundled trojanized npm package that launches NodeRabbit.
  • PollCat is delivered in a trojanized React coding challenge; loading the application starts the malware before OTP authentication.
  • PollCat forwards submitted OTP codes to an attacker-managed URL.
Defensive Notes
  • The article says reviewing the challenge source and investigating unfamiliar npm imports could reveal a trojanized project.
  • Kaspersky products detect the threat as Trojan.JS.MirageKitten.*.

Indicators of compromise

TypeIndicatorContext
DOMAINaceofspadesmanagement[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINcrossdwm[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINdigimediaskill[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINdnshnsdev[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINgamebarapp[.]azurewebsites[.]netPollCat C2 domain.
DOMAINgamebarappinformation[.]azurewebsites[.]netPollCat C2 domain.
DOMAINglmediaagency[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINgreenyjsgfd[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINhealthcomfsdpower[.]comNodeRabbit C2 domain.
DOMAINhealthful-hub[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINhealthfullyrecipes[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINhealthvitalitycare[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINhealthyweightplan[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINhecowime-aqdphyd4bbdef6es[.]westeurope-01[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINhelptellerbls[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINhpjumpsrv[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINkyrasey-f8hfexa5cqamh7fk[.]westeurope-01[.]azurewebsites[.]netNodeRabbit C2 domain.
DOMAINlifespotify[.]comPollCat C2 domain, also used to receive OTP submissions.
DOMAINmens-health-online[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINmsmanagementgrp[.]comDomain identified as Mirage Kitten operational infrastructure.
DOMAINmsmanagementgrpmedia[.]comNodeRabbit infrastructure domain listed in the article.
DOMAINnaturalapplication[.]azurewebsites[.]netDomain listed as Mirage Kitten campaign infrastructure.
DOMAINneumedicahealthcare[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINoptimumhealthcredit[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINplugplay[.]azurewebsites[.]netNodeRabbit C2 domain.
DOMAINrefreshhealthandwellness[.]comAdditional infrastructure attributed to Mirage Kitten.
DOMAINretaildemo[.]azurewebsites[.]netDomain listed as Mirage Kitten campaign infrastructure.
DOMAINrgbteller[.]azurewebsites[.]netNodeRabbit C2 domain listed in the infrastructure table.
DOMAINsahi-finance[.]comPollCat C2 domain.
DOMAINstorview[.]azurewebsites[.]netNodeRabbit infrastructure domain listed in the article.
DOMAINtimedrv[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINtubitak[.]azurewebsites[.]netNodeRabbit infrastructure domain listed in the article.
DOMAINuserwellgtfs[.]azurewebsites[.]netNodeRabbit infrastructure domain listed in the article.
DOMAINvisitfinancedentists[.]comNodeRabbit C2 domain.
DOMAINwdisystem[.]azurewebsites[.]netDomain listed as NodeRabbit campaign infrastructure.
DOMAINwslmenus[.]azurewebsites[.]netNodeRabbit infrastructure domain listed in the article.
DOMAINwslwebui[.]azurewebsites[.]netNodeRabbit C2 domain.
MD50962f56d7ec69f4f2a0162dcbe22116bHash of the trojanized Case-34234.zip archive.
MD51ea83e4e4592b01e4acab63eb867bee5Hash of the trojanized Front-Technical-Challenge.zip archive.
MD5291ac3abe73c5158e59a437b75d5f0aaHash of the trojanized Project-1802.zip archive.
MD5366515822d5ac1cc500711ef57a2e32eHash of Task-FullStack.zip, listed as a trojanized project archive.
MD5795e053a990a1569ffdcb57f48f6d085Hash of the trojanized RankChallenge-react-6uJSX3-main.zip archive.
MD5810f8e3b88eb05f710c09552941d6f56Hash of the Retrograde/MiniFast native DLL backdoor cited in the malware comparison.
MD5be086789568441d0d7e4679aee51f566Hash of the trojanized challenges-17831.zip archive.
MD5cbaaf0900a13f28e380f49adecec932cHash of FrontEnd-Task.zip, listed as a trojanized project archive.
MD5cf449f1992c2819e62ac44a0b06ac2e7Hash of the trojanized fullstack-1536.zip archive.
MD5de5af16a3757ef700b01dc34d67079aeHash of the trojanized webapp76531.zip archive.
MD5e259c5edf158aac4cfe14f77ddd0b196Hash of the trojanized challenges-17832.zip archive.
MD5e95a4366686e3f786ea3c056fab5b0daHash of the trojanized webapp76592.zip archive.
URLhxxps[:]//lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validateAttacker-managed URL that receives OTP codes submitted through the trojanized challenge.
URLhxxps[:]//oracle-challenge[.]s3[.]us-east-1[.]amazonaws[.]com/Front-Technical-Challenge[.]zipSpecific trojanized coding-challenge archive URL identified as payload delivery infrastructure.

MITRE ATT&CK

T1016 · System Network Configuration DiscoveryNodeRabbit enumerates network adapters, MAC and IP addresses, and DNS settings.T1027 · Obfuscated Files or InformationPollCat is described as obfuscated JavaScript.T1033 · System Owner/User DiscoveryNodeRabbit and PollCat collect usernames and other user or domain information.T1036.005 · Match Legitimate Resource Name or LocationNodeRabbit variant 2 masquerades as Intel Driver & Support Assistant.T1041 · Exfiltration Over C2 ChannelPollCat uploads local files or file chunks to its C2.T1053.003 · CronNodeRabbit and PollCat add Linux cron entries, including @reboot entries, for persistence.T1053.005 · Scheduled TaskNodeRabbit and PollCat create Windows scheduled tasks to relaunch their payloads.T1057 · Process DiscoveryThe malware lists running processes and PollCat collects process names.T1059.005 · Visual BasicNodeRabbit's WSL persistence writes a launcher.vbs file and invokes it through wscript.exe.T1059.007 · JavaScriptNodeRabbit and PollCat execute JavaScript malware using Node.js.T1071.001 · Web ProtocolsThe malware uses HTTP(S) requests to register with C2, poll for commands, and submit results.T1082 · System Information DiscoveryNodeRabbit and PollCat collect host and operating-system information for C2 registration.T1083 · File and Directory DiscoveryNodeRabbit lists and reads files, while PollCat inventories directories and searches development locations.T1105 · Ingress Tool TransferPollCat retrieves files from its C2 through the /vault/<uuid> endpoint and writes them to the victim machine.T1114.001 · Local Email CollectionNodeRabbit variant 3 harvests account addresses from Outlook OST and PST artifacts.T1176 · Software ExtensionsNodeRabbit variant 3 installs a fake VS Code extension that starts the payload.T1204.002 · Malicious FileTargets are pressured to download and run trojanized coding-challenge projects.T1497.001 · System ChecksNodeRabbit variant 2 checks system resources, uptime, usernames, hostnames, and running analysis tools before deciding whether to exit.T1518.001 · Security Software DiscoveryPollCat inventories selected software directories and searches for folders associated with named security-software vendors.T1543.001 · Launch AgentNodeRabbit and PollCat create macOS LaunchAgent configuration files to relaunch their payloads.T1547.001 · Registry Run Keys / Startup FolderNodeRabbit creates Windows Run registry values for persistence.T1566.002 · Spearphishing LinkFake recruiter outreach directs targets to coding challenges through links on job-search platforms.T1573.001 · Symmetric CryptographyNodeRabbit encrypts C2 request data with AES-256-GCM.

Threat Actors

Malware

Vendors

Products

Countries

Industries

Related Articles