< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 4 sources · 1 days · First seen · Last updated

Iran-linked cyberattacks targeting software developers

Overview

Cybersecurity researchers have identified a sophisticated cyberattack campaign conducted by Iran-linked threat actors, specifically groups identified as Mirage Kitten (also known as UNC1549, Smoke Sandstorm, or Nimbus Manticore).

The attackers utilize social engineering on platforms like LinkedIn, posing as recruiters to target software engineers and developers in sectors such as aerospace, aviation, and financial technology. The campaign involves inviting targets to complete technical coding challenges hosted on legitimate cloud storage services. These challenges often include instructions prohibiting the use of AI assistants, a tactic likely intended to prevent AI-driven security tools from detecting malicious code.

Technically, the campaign marks a shift for these groups, moving from Windows-specific languages like C and C++ to Node.js and JavaScript-based malware. This transition allows for the deployment of cross-platform remote access trojans, such as the newly documented NodeRabbit and PollCat, which can infect Linux and macOS systems. While initial activity was noted in Afghanistan, Egypt, and Ethiopia, the campaign has expanded to include targets in Turkey, Germany, Israel, India, and Ireland.

Entities

Kaspersky · LinkedIn · Mirage Kitten · Nimbus Manticore · Mirage Kitten

Timeline

  1. 10 days ago

    [TECHNOLOGY] 2 sources
    Mirage Kitten targets developers via LinkedIn fake job offers

    The Mirage Kitten threat group is using fake LinkedIn job offers and Node.js-based malware to target aerospace and fintech developers globally.

  2. 11 days ago

    [TECHNOLOGY] 2 sources
    Iran-linked hackers use fake coding tests to spread malware

    Iran-linked hackers are using fake LinkedIn coding challenges to spread NodeRabbit and PollCat malware, specifically instructing candidates not to use AI tools to avoid detection of the malicious code.

Sources

borncity.com · cybernoz.com · donanimgunlugu.com · thehackernews.com