Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 4 sources · 1 days · First seen · Last updated
Iran-linked cyberattacks targeting software developers
Overview
Cybersecurity researchers have identified a sophisticated cyberattack campaign conducted by Iran-linked threat actors, specifically groups identified as Mirage Kitten (also known as UNC1549, Smoke Sandstorm, or Nimbus Manticore).
The attackers utilize social engineering on platforms like LinkedIn, posing as recruiters to target software engineers and developers in sectors such as aerospace, aviation, and financial technology. The campaign involves inviting targets to complete technical coding challenges hosted on legitimate cloud storage services. These challenges often include instructions prohibiting the use of AI assistants, a tactic likely intended to prevent AI-driven security tools from detecting malicious code.
Technically, the campaign marks a shift for these groups, moving from Windows-specific languages like C and C++ to Node.js and JavaScript-based malware. This transition allows for the deployment of cross-platform remote access trojans, such as the newly documented NodeRabbit and PollCat, which can infect Linux and macOS systems. While initial activity was noted in Afghanistan, Egypt, and Ethiopia, the campaign has expanded to include targets in Turkey, Germany, Israel, India, and Ireland.
Entities
Kaspersky · LinkedIn · Mirage Kitten · Nimbus Manticore · Mirage Kitten
Timeline
-
10 days ago
[TECHNOLOGY] 2 sourcesMirage Kitten targets developers via LinkedIn fake job offersThe Mirage Kitten threat group is using fake LinkedIn job offers and Node.js-based malware to target aerospace and fintech developers globally.
-
11 days ago
[TECHNOLOGY] 2 sourcesIran-linked hackers use fake coding tests to spread malwareIran-linked hackers are using fake LinkedIn coding challenges to spread NodeRabbit and PollCat malware, specifically instructing candidates not to use AI tools to avoid detection of the malicious code.
Sources
borncity.com · cybernoz.com · donanimgunlugu.com · thehackernews.com