Zero Day Room
Live
Regulation & compliance

Mirage Kitten deploys NodeRabbit and PollCat

Kaspersky researchers discovered the Mirage Kitten APT group using new Node.js and JavaScript-based malware, NodeRabbit and PollCat, delivered via

Kaspersky researchers discovered the Mirage Kitten APT group using new Node.js and JavaScript-based malware, NodeRabbit...

Kaspersky researchers have uncovered two new malware families, NodeRabbit and PollCat, deployed by the advanced persistent threat group Mirage Kitten. The group is using these cross-platform remote access trojans (RATs) to target the aviation and financial technology sectors across the Middle East and Africa. The malware is delivered through spear-phishing messages on LinkedIn and other job search platforms, which contain trojanized coding challenge archives.

According to Kaspersky's report, this marks the first publicly documented use of Node.js- and JavaScript-based malware by Mirage Kitten, a group historically reliant on native code written in C, C++, and Go. The initial NodeRabbit sample was identified on a system in Afghanistan, with further variants found on systems in Egypt and Ethiopia.

Initial Access via Trojanized Coding Challenges

The infection chain begins with fake recruiter accounts contacting software engineers on job platforms. A threat actor posing as a talent acquisition specialist at a major technology company would advertise a job opening and invite the target to complete a technical assessment. The target received a link to a coding challenge hosted on an Amazon S3 bucket and was pressured to download and run the project immediately.

One such archive, Front-Technical-Challenge.zip, purported to contain a coding challenge for an engineering role. Its README instructed candidates to review and fix defects in a frontend application built with Express, React, and Vite. It claimed the server.js file was bug-free and should not be modified, directing attention away from the only file the attackers had altered. The README also imposed a three-hour time limit and prohibited the use of AI assistants.

The first line of server.js imported a trojanized npm package named colorized_terminal, version 2.1.0. The attackers bundled the package directly in the archive's node_modules directory. When imported, the package silently launched an implant from node_modules/.cache/.320697f1/index.js as a detached background process.

NodeRabbit RAT Variants and Capabilities

Kaspersky identified three NodeRabbit variants with a shared code lineage, each delivered through similarly themed coding challenges using the trojanized packages colorized_terminal and pretty-log, both pinned to version 2.1.0. The malware is a cross-platform RAT built with Node.js, targeting Windows, Linux, and macOS.

VariantLocation FoundTrojanized PackageKey Features
FirstAfghanistancolorized_terminalBasic persistence, fixed local port (127.0.0.1:48739), 11 commands.
SecondEgyptpretty-logAnti-analysis checks, corporate proxy support, host-specific listener port.
ThirdEthiopiapretty-logUpdated C2 endpoints, 23 total commands, additional persistence mechanisms.

The first variant generates a unique agent identifier from host information and uses a TCP listener as a single-instance mechanism. It communicates with command-and-control servers through three API endpoints on Azure-hosted infrastructure, using AES-256-GCM encryption. The second variant is more advanced. It checks for analysis environments, terminating if it detects limited memory, low CPU count, short uptime, or analyst tools. Before exiting, it generates benign HEAD requests to major websites. It also implements corporate proxy support, checking environment variables and Windows settings. For persistence, it masquerades as the Intel Driver & Support Assistant.

The third variant retains much of the second's functionality but introduces changes to its C2 configuration and command set. It uses a different set of API endpoints and a C2 chain composed of Azure- and Cloudflare-hosted domains. A new command, agent:servers, can replace the active C2 server list. This variant adds 12 new commands to the original 11.

PollCat and Detection

During the same investigation, researchers discovered another previously undocumented malware family dubbed PollCat. Like NodeRabbit, PollCat is a cross-platform RAT written in obfuscated JavaScript and distributed through trojanized coding challenge archives. Kaspersky's products detect this threat as Trojan.JS.MirageKitten.*.

The report notes that an AI code-review assistant tasked with auditing the trojanized project would likely have flagged the suspicious first-line import of the unknown npm package, warning the targeted developer. The group's shift to scripting languages like Node.js and JavaScript represents a significant evolution in their toolkit, moving away from their historical reliance on compiled native malware often deployed through DLL search-order hijacking.

Related coverage

More from Regulation & compliance