IRAN-LINKED APT Mirage Kitten has developed a new malware distribution method that exploits fake LinkedIn job tests to deliver two malware families: NodeRabbit and PollCat. These are designed to evade detection by instructing victims not to use AI tools during their coding assessments. NodeRabbit runs on multiple operating systems and includes sophisticated evasion techniques to avoid analysis. PollCat masquerades as a timed coding challenge where the malware activates before the victim inputs an access code.
Both malware strains are linked to earlier threats and target organizations in the fintech and aviation sectors in the Middle East and Africa. This marks a shift in Mirage Kitten's approach to malware delivery while maintaining its focus on cyberespionage.