Article may be outdated

This article is 3 days old. Some details may have changed since publication.

securelist.com·4 min read·hard

Mirage Kitten switches to Node.js and JavaScript malware

O
Omar Amin
Mirage Kitten switches to Node.js and JavaScript malware
AI Summary

Security researchers have identified a new malware campaign by the APT group Mirage Kitten that utilizes Node.js and JavaScript-based remote access trojans. The malware is distributed via trojanized coding challenges sent to job applicants.

Why it matters

This shift in tactics demonstrates how threat actors are evolving to use common development tools to bypass traditional security defenses.

Dive DeeperCreate a free account to unlock

While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia.

NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives.

During the same investigation, we discovered another previously undocumented malware family that we dubbed PollCat. Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in