Iranian cyber spies target aviation, fintech developers with new malware

An Iran-linked cyberespionage group known as Mirage Kitten is targeting tech professionals in aviation and finance with fake job offers. The attackers use malicious coding assignments to distribute undocumented malware capable of remote system access.
Why it matters
This campaign highlights the evolving sophistication of state-sponsored cyber threats that exploit professional hiring processes to compromise critical infrastructure sectors.
An Iran-linked cyberespionage group is targeting technology specialists in the aviation, aerospace and financial sectors with fake job offers designed to trick them into installing previously undocumented malware, according to new research.
The group, tracked by Russian cybersecurity firm Kaspersky as Mirage Kitten, has targeted developers and other specialists in Egypt, Ethiopia and Afghanistan through LinkedIn and other job platforms.
Researchers investigating the campaign uncovered two previously unknown malware families, dubbed NodeRabbit and PollCat. Both are disguised as programming assignments that victims are asked to complete as part of a purported hiring process.
NodeRabbit is a remote-access trojan capable of infecting Windows, Linux and macOS systems. Once installed, it allows attackers to collect information about the victim and their computer, create or modify files and execute additional commands, giving the hackers remote access to the compromised machine.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in