THE article details Kaspersky's discovery of two new malware families, NodeRabbit and PollCat, attributed to the threat group Mirage Kitten. NodeRabbit, a cross-platform remote access trojan (RAT) created in Node.js, primarily targets Windows, Linux, and macOS systems. It is spread through malware-laden coding challenges on platforms like LinkedIn. Researchers have identified three variants of NodeRabbit and noted a similar structure in PollCat, which operates through JavaScript.
Both families signify a shift in Mirage Kitten's tactics to include JavaScript-based attacks, broadening their reach across different platforms. The infections have been traced back to systems in Afghanistan, Egypt, and Ethiopia, affecting sectors such as FinTech and aviation. The malware employs sophisticated techniques, including proxy support and obfuscation, and uses legitimate cloud services like Amazon S3 for hosting malicious content.