Mirage Kitten is using fake LinkedIn recruiters and malicious coding tests to infect software engineers in the aviation and financial technology sectors, according to Kaspersky’s Global Research and Analysis Team (GReAT).

The cyberespionage campaign has targeted workers in Egypt, Ethiopia, and Afghanistan. Related malware has also been detected in Germany, Türkiye, Israel, India, and Ireland.

The attackers pose as talent acquisition specialists from major technology companies and contact software engineers through LinkedIn. They invite potential candidates to complete a programming test hosted on legitimate Amazon cloud storage, making the download appear trustworthy.

Candidates are given only one to three hours to finish the task and are warned against using artificial intelligence (AI) coding assistants. Kaspersky said these tools could detect the malicious code hidden in the downloaded package.

Once a developer runs the coding test, spyware installs itself in the background. The victim may remain unaware of the attack while working on the assignment.

“The transition from traditional, compiled malware to JavaScript-based threats is a pivot in Mirage Kitten’s tactics,” said Omar Amin, security expert at Kaspersky GReAT. “By hijacking the recruitment process and injecting code directly into everyday developer tools, the group can evasively get past enterprise security boundaries. Developers typically hold elevated access privileges within corporate networks, making them an incredibly high-value target for advanced cyberespionage.” 

The campaign creates a business risk because developers often have access to source code, internal systems, cloud services, and other sensitive company resources. Compromising one employee could give attackers a way into a wider corporate network.

Kaspersky identified two new types of malware used in the attacks. NodeRabbit is a Node.js remote access trojan hidden in common software development packages. It allows attackers to control an infected computer.

NodeRabbit can also install fake extensions that run with Microsoft Visual Studio Code. It may change local code repositories so the malware launches when a developer saves or merges code.

The second malware, PollCat, is a JavaScript remote access trojan. It asks candidates to enter a one-time password supplied by the supposed recruiter. After activation, it collects information about the computer, searches folders, and sends data to the attackers.

Using Node.js and JavaScript allows Mirage Kitten to target Windows, macOS, and Linux with largely the same code. The group previously relied on programs written in C, C++, or Go, mainly for Windows computers.

Kaspersky advised companies to monitor employee devices, strengthen threat detection and response, investigate possible compromises, and give security teams updated information on emerging attacks.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading