KASPERSKY Clouded the Mirage Kitten operation as a cyberespionage campaign in which software developers across aviation, aerospace, and fintech sectors are targeted. The attackers pose as recruiters on professional networks (notably LinkedIn), inviting victims to complete a technical assessment. Victims are directed to a ZIP archive containing a coding challenge hosted on a legitimate Amazon S3 bucket.
The arrangement appears routine, with constraints such as banning AI assistants and a tight three-hour window intended to prevent automated analysis, but the archive hides malicious payloads.
Once opened, the archive delivers a dual backdoor infection. A trojanised package, imported by a legitimate-looking backend file named colorized_terminal, silently launches Mirage Kitten malware and a separate remote access trojan named PollCat. Mirage Kitten creates a unique host-based identifier, hashes elements like hostname, username, and OS version, and establishes OS-specific persistence (hiding as an Edge update on Windows and launching persistent launch agents on macOS).
PollCat, distributed via a separate React-based project, begins polling for commands even before user authentication completes, indicating a pre-emptive capability to receive instructions. Both backdoors are reported to operate natively across Windows, Linux, and macOS. Kaspersky’s analysis attributes the activity with high confidence to Mirage Kitten (UNC1549/Smoke Sandstorm), noting a strategic shift to cross-platform scripting and the use of Azure subdomains to blend traffic with normal activity.
The campaign has seen infections in Afghanistan, Egypt, and Ethiopia, with detections in India, Germany, and Ireland, and highlights the risk of deep access to developer workstations and potential intellectual property loss.