{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/developer-targeting/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Mirage Kitten"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["phishing","malware","rat","developer-targeting"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eThe Mirage Kitten APT group has launched a new campaign targeting software engineers within the aviation and FinTech sectors. The campaign utilizes a sophisticated delivery mechanism involving fake recruiter outreach on professional networking platforms like LinkedIn. Victims are invited to complete technical coding assessments, which are hosted on Amazon S3 buckets. These archives contain trojanized software development projects - specifically an application named TaskFlow - that include malicious npm packages such as 'colorized_terminal' (v2.1.0) and 'pretty-log' (v2.1.0).\u003c/p\u003e\n\u003cp\u003eOnce executed, these packages trigger the installation of 'NodeRabbit', a previously undocumented, cross-platform remote access trojan (RAT) written in Node.js. NodeRabbit is capable of executing arbitrary shell commands, performing system reconnaissance, and establishing persistent backdoors on Windows, Linux, and macOS systems. During the same investigation, researchers identified a secondary RAT named 'PollCat', written in obfuscated JavaScript. This represents a significant shift in the group's tradecraft from native C/C++ or Go malware to high-level language-based implants, likely intended to blend into developer environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMirage Kitten operators perform reconnaissance and reach out to targets on job search platforms posing as recruiters.\u003c/li\u003e\n\u003cli\u003eThe target receives a link to a project archive (e.g., Front-Technical-Challenge.zip) hosted on Amazon S3.\u003c/li\u003e\n\u003cli\u003eThe victim downloads and extracts the archive, which includes a malicious npm package dependency in the \u003ccode\u003enode_modules\u003c/code\u003e directory.\u003c/li\u003e\n\u003cli\u003eUpon running the development project, the malicious package executes an implant from \u003ccode\u003enode_modules/.cache/.320697f1/index.js\u003c/code\u003e as a background process.\u003c/li\u003e\n\u003cli\u003eThe implant (NodeRabbit) generates a unique agent ID based on host system metadata and attempts to bind to a local TCP port to ensure single-instance operation.\u003c/li\u003e\n\u003cli\u003ePersistence is established: via Windows Registry \u003ccode\u003eRun\u003c/code\u003e keys for \u003ccode\u003enodew.exe\u003c/code\u003e, cron jobs on Linux, or LaunchAgents on macOS.\u003c/li\u003e\n\u003cli\u003eThe malware initiates beaconing to Azure-hosted C2 infrastructure using AES-256-GCM encrypted JSON payloads.\u003c/li\u003e\n\u003cli\u003eThe final objective is achieved via arbitrary command execution and exfiltration of system information or developer assets.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign targets high-value individuals within the aviation and FinTech sectors, posing a significant risk of intellectual property theft, unauthorized access to secure development environments, and potential follow-on compromise of critical corporate infrastructure. The usage of job search lures exploits the trust relationship inherent in the hiring process, making it difficult for standard email filters to flag the activity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for suspicious process execution patterns related to Node.js implants.\u003c/li\u003e\n\u003cli\u003eBlock outbound connections to the identified Azure-hosted C2 infrastructure at the network perimeter.\u003c/li\u003e\n\u003cli\u003eImplement strict controls on the execution of developer environments; verify the integrity of \u003ccode\u003enode_modules\u003c/code\u003e and external project dependencies before execution.\u003c/li\u003e\n\u003cli\u003eHunt for the presence of the identified malicious file paths and registry modifications on developer workstations.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T11:56:59Z","date_published":"2026-09-01T11:56:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mirage-kitten-noderabbit/","summary":"The Mirage Kitten threat actor is targeting aviation and FinTech software engineers with spear-phishing campaigns distributing trojanized coding challenge archives containing cross-platform Node.js and JavaScript backdoors.","title":"Mirage Kitten APT Deploys NodeRabbit and PollCat Backdoors via Trojanized Coding Challenges","url":"https://feed.craftedsignal.io/briefs/2026-09-mirage-kitten-noderabbit/"}],"language":"en","title":"CraftedSignal Threat Feed - Developer-Targeting","version":"https://jsonfeed.org/version/1.1"}