< Back to all clusters
[TECHNOLOGY] · Türkiye, Germany, Egypt, Ethiopia, Afghanistan · 2 sources

started · updated

Mirage Kitten targets developers via LinkedIn fake job offers

The threat actor group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, or Nimbus Manticore, has launched a sophisticated cyberattack campaign targeting software developers through LinkedIn. The group uses fake recruitment profiles, posing as talent acquisition specialists from major technology companies, to contact professionals in the aerospace, aviation, and financial technology sectors.

As part of a deceptive hiring process, attackers invite targets to participate in technical coding challenges. These challenges are delivered as files hosted on legitimate cloud storage services. Once a developer downloads and executes the task, malware is installed on their system. To prevent detection by AI-powered coding assistants, attackers often impose strict time limits on the tests and forbid the use of such tools.

A significant technical shift in this campaign is the group's transition to using Node.js and JavaScript-based malware. This marks the first documented instance of the group utilizing these cross-platform technologies for their attack tools, moving away from their previous reliance on Windows-specific programs written in C, C++, or Go. While the campaign primarily focuses on targets in Egypt, Ethiopia, and Afghanistan, malicious activity has also been detected in Turkey, Germany, Israel, India, and Ireland.

Entities

Kaspersky · LinkedIn · Mirage Kitten