Iranian cyber spies target aviation, fintech developers with new malware
Iranian cyber spies, tracked as Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore), are using fake job offers to trick technology specialists in Africa and the Middle East – particularly in aviation, aerospace, and fintech – into installing new malware families, NodeRabbit and PollCat. These malware families allow attackers to remotely access compromised systems, steal information, and deliver additional malicious files. The group leverages legitimate cloud infrastructure to evade detection.
Iranian cyber spies, tracked as Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore), are targeting technology specialists in Africa and the Middle East – particularly in aviation, aerospace, and fintech – with a sophisticated cyberespionage campaign. The group uses fake job offers on platforms like LinkedIn to lure victims into installing previously undocumented malware families: NodeRabbit and PollCat. These malware families allow attackers to remotely access compromised systems, steal information, and deliver additional malicious files.
The campaign begins with recruiters contacting potential victims on job-search platforms with seemingly legitimate tech job offers. In one documented case, an attacker posing as a recruiter for an unnamed major technology company approached a software engineer and asked them to complete a technical assessment. The victim was directed to download a coding challenge hosted on Amazon's cloud storage service and encouraged to run the project immediately.
One malicious archive found in Afghanistan contained a coding test that instructed candidates to review an application and fix its flaws within three hours. The test explicitly banned the use of AI assistants, which Kaspersky researchers said may have been intended to prevent such tools from detecting the malicious code hidden in the project. When the developer ran the coding project, the hidden malicious component executed alongside it.
Researchers uncovered a similar technique involving PollCat, another previously undocumented malware family designed to provide attackers with persistent access to compromised computers and deliver additional malicious files. In this campaign, targets were given one hour to complete a programming test and needed a six-digit access code provided by the recruiter. The codes were described as single-use and valid only for a short time, putting additional pressure on candidates to open the project quickly.
Mirage Kitten also uses legitimate Microsoft Azure and Cloudflare infrastructure to make its activity harder to detect and track. In some cases, the hackers included the targeted organization’s name in an Azure subdomain, making communications between an infected device and their servers look more like normal corporate network traffic.
Mirage Kitten, also tracked by other cybersecurity researchers, is an Iranian state-backed cyberespionage group that has been active since at least 2022. The latest victims fit Mirage Kitten’s established focus on organizations in Africa and the Middle East, with the group particularly targeting the aviation, aerospace, and financial technology sectors.
