#NodeRabbit
An Iran-linked espionage group is using job recruitment scams to infect devices with new malware strains therecord.media/iranian-cybe...
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
therecord.media
September 1, 2026 at 12:45 PM
Nimbus Manticore uses Node.js/JavaScript cross-platform RATs NodeRabbit and PollCat, delivered via trojanized coding challenge archives, to likely expand Linux and macOS targeting.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 1, 2026 at 1:21 PM
~Kaspersky~
Mirage Kitten used trojanized coding challenges to deliver cross-platform RATs to Middle East and African targets.
-
IOCs: plugplay[.]azurewebsites[.]net, visitfinancedentists[.]com, sahi-finance[.]com
-
#APT #Malware #ThreatIntel
Mirage Kitten Deploys NodeRabbit and PollCat
securelist.com
September 1, 2026 at 12:46 PM
Another thing Trump hath Wrought:
Job seekers: Beware the Iranian Spear fishers on those job posting sites...
thehackernews.com/2026/09/iran...
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
thehackernews.com
September 6, 2026 at 2:26 PM
Iranian cyber spies target aviation, fintech developers with new malware therecord.media/iranian-cybe...
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
therecord.media
September 13, 2026 at 6:12 PM
Fake interviews on LinkedIn are now malware drop points: NodeRabbit & PollCat infiltrate dev machines via staged code tests. #Cybersecurity #RAT #NodeRabbit #PollCat #CyberAttack #DeveloperSecurity thedailytechfeed.com/fake-linkedi...
September 9, 2026 at 4:05 PM
🚨 Attackers exploit fake LinkedIn job offers, disguising malware as coding challenges — a sharp reminder that social engineering thrives in everyday professional routines.

🌐 cyberfrogsecurity.com/blog/securit...

#LinkedInScam #FakeJobOffers #SocialEngineering

Try it for FREE 🆓
Cyber Security Awareness: Fake LinkedIn Job Offers | Cyberfrog
✓ Cyber Security Awareness guidance on fake LinkedIn job offers, NodeRabbit and PollCat RATs, phishing training, and practical human-risk reduction for teams.
cyberfrogsecurity.com
September 11, 2026 at 9:31 AM
Mirage Kitten Malware Targets Aviation and Fintech Sectors(Mirage Kitten、航空・FinTechを狙う新マルウェア「NodeRabbit」「PollCat」を展開) #SecurityOnline (Sep 8)

securityonline.info/mirage-kitte...
https://securityonline.info/mirage-kitten-malware-noderabbit-pollcat/
securityonline.info
September 8, 2026 at 10:00 PM
イラン系ハッカー、偽のLinkedIn求人情報を悪用しNodeRabbitとPollCatのRATを展開

イラン系のサイバースパイグループ「Mirage Kitten」が、LinkedInや求人検索プラットフォーム上で偽の採用担当者を装い、ソフトウェアエンジニアを標的にしていることが判明しました。 攻撃者はトロイの木馬化したコーディング課題を利用し、これまで報告されていなかった2種類のクロスプラットフォーム型リモートアク...
イラン系ハッカー、偽のLinkedIn求人情報を悪用しNodeRabbitとPollCatのRATを展開
イラン系のサイバースパイグループ「Mirage Kitten」が、LinkedInや求人検索プラットフォーム上で偽の採用担当者を装い、ソフトウェアエンジニアを標的にしていることが判明しました。 攻撃者はトロイの木馬化したコーディング課題を利用し、これまで報告されていなかった2種類のクロスプラットフォーム型リモートアク
blackhatnews.tokyo
September 9, 2026 at 1:04 PM
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware

Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to ma…
#hackernews #news
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to use AI tools while reviewing the trojanized code they were […]
securityaffairs.com
September 3, 2026 at 10:22 AM
🚨 Mirage Kitten shows how phishing is getting sharper — cleaner infrastructure, smarter lures, harder detection.

🌐 spoofguard.io/blog/en/phis...

#CyberSecurity #ThreatIntel #Phishing #MirageKitten #SpoofGuard #Infosec

Try it for FREE. 🆓
Phishing Detection: Mirage Kitten’s Fake Coding Tests | Spoofguard.io
✓ Phishing detection teams should watch Mirage Kitten’s fake coding tests, where NodeRabbit and PollCat RATs target developers through job-related lures.
spoofguard.io
September 3, 2026 at 8:18 AM
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware: securityaffairs.com/198289/apt/i...
Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware
Mirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware.
securityaffairs.com
September 2, 2026 at 11:11 PM
Výzkumníci z laboratoře Kaspersky nadále sledují aktivity skupiny Mirage Kitten a informují o objevu dosud neznámé rodiny škodlivého softwaru s názvem NodeRabbit. První vzorek byl zjištěn v systému v Afghánistánu.
September 2, 2026 at 11:47 AM
Iranian cyber spies target aviation, fintech developers with new malware | The Record from Recorded Future News
therecord.media/iranian-cybe...
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
therecord.media
September 2, 2026 at 9:42 PM
Kaspersky uncovers NodeRabbit and PollCat, new cross-platform RATs from Mirage Kitten, delivered via fake coding challenges on LinkedIn.
Mirage Kitten Debuts Node.js and JavaScript Malware
Kaspersky uncovers NodeRabbit and PollCat, new cross-platform RATs from Mirage Kitten, delivered via fake coding challenges on LinkedIn.
www.technobezz.com
September 1, 2026 at 10:45 PM
📢 Mirage Kitten cible l'aviation et la FinTech au Moyen-Orient et en Afrique avec NodeRabbit et PollCat

Cet article de recherche documente la découverte de deux nouvelles familles de malwares attribuées à Mirage Kitten (également…

🟢 vérification factuelle haute
#FinTech #MirageKitten #Cyberveille
Mirage Kitten cible l'aviation et la FinTech au Moyen-Orient et en Afrique avec NodeRabbit et PollCat
Cet article de recherche documente la découverte de deux nouvelles familles de malwares attribuées à Mirage Kitten (également connu sous les noms UNC1549, Smoke Sandstorm, Nimbus Manticore), un groupe APT ciblant historiquement le Moyen-Orient et l'Afrique. La campagne repose sur une technique de faux recruteur (recruiter persona) sur LinkedIn et d'autres plateformes d'emploi.
cyberveille.ch
September 1, 2026 at 11:00 PM
Miraj・キトゥン、偽コーディングチャレンジでNodeRabbitとPollCatのRATを展開

イランと関連のある脅威アクター「Mirage Kitten」が、ソフトウェア開発者を標的に偽の採用選考課題を送りつけ、その中に新たに確認された2種類のクロスプラットフォーム型リモートアクセス型トロイの木馬「NodeRabbit」と「PollCat」を仕込んでいることが分かりました。 今回のキャンペーンでは、Linke...
Miraj・キトゥン、偽コーディングチャレンジでNodeRabbitとPollCatのRATを展開
イランと関連のある脅威アクター「Mirage Kitten」が、ソフトウェア開発者を標的に偽の採用選考課題を送りつけ、その中に新たに確認された2種類のクロスプラットフォーム型リモートアクセス型トロイの木馬「NodeRabbit」と「PollCat」を仕込んでいることが分かりました。 今回のキャンペーンでは、Linke
blackhatnews.tokyo
September 1, 2026 at 1:34 PM
Iranian cyber spies target aviation, fintech developers with new malware

In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
therecord.media
September 1, 2026 at 12:41 PM
Nimbus Manticore uses Node.js/JavaScript cross-platform RATs NodeRabbit and PollCat, delivered via trojanized coding challenge archives, to likely expand Linux and macOS targeting.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 1, 2026 at 1:23 PM
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
September 1, 2026 at 7:47 AM
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

thehackernews.com/2026/09/iran...

#Kyberturvallisuus #Tietomurto
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
thehackernews.com
September 1, 2026 at 1:34 PM