securelist.com 9/1/2026, 7:16:22 AM · external

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

THE article details Kaspersky's discovery of two new malware families, NodeRabbit and PollCat, attributed to the threat group Mirage Kitten. NodeRabbit, a cross-platform remote access trojan (RAT) created in Node.js, primarily targets Windows, Linux, and macOS systems. It is spread through malware-laden coding challenges on platforms like LinkedIn. Researchers have identified three variants of NodeRabbit and noted a similar structure in PollCat, which operates through JavaScript.

Both families signify a shift in Mirage Kitten's tactics to include JavaScript-based attacks, broadening their reach across different platforms. The infections have been traced back to systems in Afghanistan, Egypt, and Ethiopia, affecting sectors such as FinTech and aviation. The malware employs sophisticated techniques, including proxy support and obfuscation, and uses legitimate cloud services like Amazon S3 for hosting malicious content.

View full article

Article by CyberSIXT