# Iran-linked cyberattacks targeting software developers

> Live situation record from CLSTR: https://clstr.news/situations/iran-linked-cyberattacks-targeting-software-developers
> Updated: 2026-09-02T06:02:10.000Z. Sources: 4. Developments: 2.

Cybersecurity researchers have identified a sophisticated cyberattack campaign conducted by Iran-linked threat actors, specifically groups identified as Mirage Kitten (also known as UNC1549, Smoke Sandstorm, or Nimbus Manticore). 

The attackers utilize social engineering on platforms like LinkedIn, posing as recruiters to target software engineers and developers in sectors such as aerospace, aviation, and financial technology. The campaign involves inviting targets to complete technical coding challenges hosted on legitimate cloud storage services. These challenges often include instructions prohibiting the use of AI assistants, a tactic likely intended to prevent AI-driven security tools from detecting malicious code.

Technically, the campaign marks a shift for these groups, moving from Windows-specific languages like C and C++ to Node.js and JavaScript-based malware. This transition allows for the deployment of cross-platform remote access trojans, such as the newly documented NodeRabbit and PollCat, which can infect Linux and macOS systems. While initial activity was noted in Afghanistan, Egypt, and Ethiopia, the campaign has expanded to include targets in Turkey, Germany, Israel, India, and Ireland.

## Timeline

### 2026-09-02: Mirage Kitten targets developers via LinkedIn fake job offers

The Mirage Kitten threat group is using fake LinkedIn job offers and Node.js-based malware to target aerospace and fintech developers globally.

2 sources. https://clstr.news/cluster/mirage-kitten-targets-developers-via-linkedin-fake-job-offers

### 2026-09-01: Iran-linked hackers use fake coding tests to spread malware

Iran-linked hackers are using fake LinkedIn coding challenges to spread NodeRabbit and PollCat malware, specifically instructing candidates not to use AI tools to avoid detection of the malicious code.

2 sources. https://clstr.news/cluster/iran-linked-hackers-use-fake-coding-tests-to-spread-malware

---
Cite as: Iran-linked cyberattacks targeting software developers. CLSTR, https://clstr.news/situations/iran-linked-cyberattacks-targeting-software-developers
