Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky identified NodeRabbit and PollCat, two previously undocumented cross-platform remote access trojans deployed by the Mirage Kitten APT group. NodeRabbit is a Node.js RAT delivered through trojanized coding challenge archives on job search platforms, communicating with Azure-hosted C2 endpoints using AES-256-GCM encryption. PollCat is an obfuscated JavaScript RAT using HTTP polling with a custom C2 protocol that treats HTTP 400 responses as successful registration and shares structural similarities with the Retrograde/MiniFast backdoor. Both malware families target Windows, Linux, and macOS, with NodeRabbit variant 3 introducing persistence via fake VS Code extensions and Git hook injection.
- domainaceofspadesmanagement[.]comMirage Kitten infrastructure domain, registered 2026-05-18 via NameCheap
- domaincrossdwm[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domaindigimediaskill[.]comMirage Kitten infrastructure domain, registered 2026-05-18 via NameCheap
- domaindnshnsdev[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domaingamebarapp[.]azurewebsites[.]netPollCat C2 server on Azure Websites, MarkMonitor-registered
- domaingamebarappinformation[.]azurewebsites[.]netPollCat C2 server on Azure Websites, MarkMonitor-registered
- domainglmediaagency[.]comMirage Kitten infrastructure domain, registered 2026-05-18 via NameCheap
- domaingreenyjsgfd[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainhealthcomfsdpower[.]comNodeRabbit variant 3 C2 server, Cloudflare-backed domain used in the C2 chain alongside Azure-hosted infrastructure
- domainhealthful-hub[.]comMirage Kitten infrastructure domain, registered 2026-07-03 via NameCheap
- domainhealthfullyrecipes[.]comMirage Kitten infrastructure domain, registered 2026-06-30 via NameCheap
- domainhealthvitalitycare[.]comMirage Kitten infrastructure domain, registered 2026-05-18 via NameCheap
- domainhealthyweightplan[.]comMirage Kitten infrastructure domain, registered 2026-05-18 via NameCheap
- domainhecowime-aqdphyd4bbdef6es[.]westeurope-01[.]azurewebsites[.]netNodeRabbit C2 domain on Azure West Europe region
- domainhelptellerbls[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainhpjumpsrv[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainkyrasey-f8hfexa5cqamh7fk[.]westeurope-01[.]azurewebsites[.]netNodeRabbit variant 3 C2 server on Azure West Europe region
- domainlifespotify[.]comAttacker-managed domain registered via Dynadot, used as OTP validation endpoint for PollCat lure and attributed to the PollCat campaign
- domainmens-health-online[.]comMirage Kitten infrastructure domain, registered 2026-05-15 via NameCheap
- domainmsmanagementgrp[.]comNodeRabbit variant 7 C2 server, MarkMonitor-registered domain on AS 8075 (Microsoft Azure)
- domainmsmanagementgrpmedia[.]comNodeRabbit variant 7 C2 domain, MarkMonitor-registered, AS 8075
- domainnaturalapplication[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainneumedicahealthcare[.]comMirage Kitten infrastructure domain, registered 2026-07-03 via NameCheap
- domainoptimumhealthcredit[.]comMirage Kitten infrastructure domain, registered 2026-07-03 via NameCheap
- domainplugplay[.]azurewebsites[.]netNodeRabbit variant 1 primary C2 server on Azure Websites; malware falls back to additional Azure-hosted C2 addresses on failure
- domainrefreshhealthandwellness[.]comMirage Kitten infrastructure domain, registered 2026-06-09 via NameCheap
- domainretaildemo[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainrgbteller[.]azurewebsites[.]netNodeRabbit variant 1 C2 fallback server on Azure Websites
- domainsahi-finance[.]comPollCat RAT primary C2 server, registered via NameCheap; PollCat iterates over C2 list until registration succeeds
- domainstorview[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domaintimedrv[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domaintubitak[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainuserwellgtfs[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainvisitfinancedentists[.]comNodeRabbit variant 3 C2 server, Cloudflare-backed domain registered via NameCheap
- domainwdisystem[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainwslmenus[.]azurewebsites[.]netNodeRabbit C2 domain, MarkMonitor-registered, AS 8075
- domainwslwebui[.]azurewebsites[.]netNodeRabbit variant 1 C2 fallback server on Azure Websites
- filename%APPDATA%\Microsoft\EdgeUpdate\msedge_update.jsNodeRabbit variant 1 Windows persistence payload copy
- filename%APPDATA%\Microsoft\NetworkPollCat Windows persistence directory where package.json and requireObject.js are written
- filename~/Library/LaunchAgents/com.harsh.requireobject.plistPollCat macOS persistence LaunchAgent with RunAtLoad and daily 09AM trigger
- filename~/Library/LaunchAgents/com.intel.dsa.helperNodeRabbit variant 2 macOS persistence LaunchAgent
- filename~/Library/LaunchAgents/com.microsoft.edgeupdate.plistNodeRabbit variant 1 macOS persistence LaunchAgent with RunAtLoad and KeepAlive parameters
- filename%LOCALAPPDATA%\Intel\DSA\idriver_support.jsNodeRabbit variant 2 Windows persistence payload, masquerading as Intel Driver and Support Assistant
- filenamenode_modules/.cache/.320697f1/index.jsHidden NodeRabbit payload location in trojanized coding challenge project, launched by colorized_terminal npm package as detached background process
- filename.sv.jsonNodeRabbit variant 3 C2 configuration file written by agent:servers command to persist updated C2 server list
- md50962f56d7ec69f4f2a0162dcbe22116bMD5 hash of Case-34234.zip, a trojanized coding challenge archive
- md51ea83e4e4592b01e4acab63eb867bee5MD5 hash of Front-Technical-Challenge.zip, the initial NodeRabbit lure archive containing trojanized colorized_terminal npm package
- md5291ac3abe73c5158e59a437b75d5f0aaMD5 hash of Project-1802.zip, a trojanized coding challenge archive
- md5366515822d5ac1cc500711ef57a2e32eMD5 hash of Task-FullStack.zip, a trojanized coding challenge archive
- md5795e053a990a1569ffdcb57f48f6d085MD5 hash of RankChallenge-react-6uJSX3-main.zip, the PollCat lure archive containing the RankChallenge React coding assessment
- md5810f8e3b88eb05f710c09552941d6f56MD5 hash of the Retrograde/MiniFast native DLL backdoor, used for attribution to Mirage Kitten based on shared C2 protocol structure
- md5be086789568441d0d7e4679aee51f566MD5 hash of challenges-17831.zip, a trojanized coding challenge archive
- md5cbaaf0900a13f28e380f49adecec932cMD5 hash of FrontEnd-Task.zip, a trojanized coding challenge archive
- md5cf449f1992c2819e62ac44a0b06ac2e7MD5 hash of fullstack-1536.zip, a trojanized coding challenge archive
- md5de5af16a3757ef700b01dc34d67079aeMD5 hash of webapp76531.zip, a trojanized coding challenge archive
- md5e259c5edf158aac4cfe14f77ddd0b196MD5 hash of challenges-17832.zip, a trojanized coding challenge archive
- md5e95a4366686e3f786ea3c056fab5b0daMD5 hash of webapp76592.zip, a trojanized coding challenge archive
- npm_packagecolorized_terminalTrojanized npm package at version 2.1.0, bundled locally in coding challenge node_modules; imports and launches NodeRabbit payload from node_modules/.cache/.320697f1/index.js as a detached background process
- registry_keyHKCU\Software\Microsoft\Windows\CurrentVersion\RunNodeRabbit variant 3 uses this Run key for persistence via fake VS Code extension when extension directory is missing on Windows
- registry_keyHKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftEdgeUpdateNodeRabbit variant 1 Windows persistence Run key, executes nodew.exe with msedge_update.js payload
- urlhxxps://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validatePollCat OTP validation endpoint on attacker-managed domain; application forwards submitted OTP codes here during the fake coding assessment
- urlhxxps://oracle-challenge[.]s3[.]us-east-1[.]amazonaws[.]com/Front-Technical-Challenge[.]zipInitial NodeRabbit lure archive hosted on Amazon S3, delivered via LinkedIn recruiter personas as a coding challenge for engineering roles
Detection / Hunteropenrouter
What Happened
Researchers at Kaspersky discovered two new malicious programs called NodeRabbit and PollCat, used by a hacking group known as Mirage Kitten. The attackers create fake recruiter profiles on LinkedIn and other job platforms, then send software engineers what appears to be a coding test for a job application. When the engineer downloads and runs the test project, hidden malicious code activates and lets the attackers control their computer remotely. The attacks target companies in aviation and financial technology across the Middle East and Africa, including Egypt, Ethiopia, and Afghanistan. This matters because the malware works on Windows, Mac, and Linux, and it communicates with its controllers through legitimate-looking web traffic to Microsoft Azure cloud services, making it hard to detect. Organizations with developers who participate in coding challenges from recruiters should verify the source before running any downloaded code and check network logs for the specific websites and file fingerprints listed in this report.
Key Takeaways
- Mirage Kitten deployed NodeRabbit and PollCat, its first publicly documented Node.js and JavaScript-based cross-platform RATs, departing from its historical use of native C/C++/Go malware
- Initial access is achieved through LinkedIn recruiter personas delivering trojanized coding challenge archives hosted on Amazon S3, targeting software engineers in aviation and FinTech sectors
- NodeRabbit communicates over AES-256-GCM encrypted HTTPS to Azure-hosted C2 endpoints; PollCat uses HTTP polling with a custom protocol that treats HTTP 400 as a successful registration response
- NodeRabbit variant 3 introduces developer-workflow persistence via fake VS Code extensions and Git hook injection, expanding beyond traditional registry, cron, and scheduled task persistence
- Attribution to Mirage Kitten is based on structural C2 protocol similarities with the Retrograde/MiniFast native DLL backdoor and shared corporate proxy authentication techniques
Affected Systems
- Windows (all NodeRabbit and PollCat variants)
- Linux (all variants, including WSL support in NodeRabbit variant 3)
- macOS (all variants)
- Node.js runtime environments on developer workstations
- Microsoft Outlook (targeted for email harvesting by NodeRabbit variant 3)
- VS Code installations (targeted for fake extension persistence by NodeRabbit variant 3)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: LinkedIn recruiter personas send trojanized coding challenge archives hosted on Amazon S3 to software engineers in aviation and FinTech sectors
- Execution: Victim runs the project; a trojanized npm package (colorized_terminal or pretty-log at version 2.1.0) imported by server.js launches a hidden JavaScript payload from node_modules/.cache/ as a detached background process
- Persistence: OS-specific mechanisms including Windows Run registry keys, scheduled tasks (IntelDriverSupportUpdate, NetSync_<username>), Linux cron entries, macOS LaunchAgents, fake VS Code extensions, and Git hook injection with '# shepherd-persist' marker
- C2: NodeRabbit encrypts requests with AES-256-GCM to Azure-hosted HTTPS endpoints (/api/rabbit/checkin, /api/rabbit/task, /api/rabbit/result); PollCat polls /beacon, /gate/hello, /gate/fetch, and /gate/submit using HTTP with HTTP 400 treated as successful registration
- Discovery and Collection: System information, running processes, file directories, and Outlook email accounts are enumerated; security software vendor folders are detected under Program Files and AppData paths
- Exfiltration: Files are read, encoded as Base64, and uploaded to C2 via dedicated endpoints (/vault/push/ for PollCat, fs:read and fs:write commands for NodeRabbit)
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Kaspersky product detection
Kaspersky products detect this threat as Trojan.JS.MirageKitten.*. No YARA, Sigma, Snort, Suricata, or SIEM queries are provided in the public article. Additional IOCs are available to Kaspersky Threat Intelligence Reporting service customers.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | The malware runs as Node.js processes using legitimate executables (node.exe, npm) on developer workstations where such activity is expected. Renamed node.exe binaries and PE subsystem modifications are visible to EDR if file monitoring covers the relevant directories. Scheduled task and registry Run key creation are typically logged by EDR. However, the JavaScript payload content and C2 logic may not be fully visible without script content scanning. |
| Network Visibility | Medium | C2 traffic uses HTTPS to Azure Websites and Cloudflare-backed domains, which may blend into legitimate organizational traffic. The specific API paths (/api/rabbit/, /gate/, /beacon, /sdk/v2/) are distinctive but require TLS inspection or proxy logging to observe. Corporate proxy support in variant 2 adds complexity by tunneling through HTTP CONNECT and delegating NTLM authentication to curl.exe. |
| Detection Difficulty | Moderate | The malware uses legitimate cloud infrastructure (Azure Websites, Amazon S3) and common developer tools (Node.js, npm) that produce expected activity on developer workstations. However, the specific C2 API paths, persistence mechanism names, renamed binaries with PE subsystem modifications, and the '# shepherd-persist' Git hook marker provide distinctive detection opportunities. Anti-analysis checks in variant 2 add complexity by generating benign traffic before terminating. |
Required Log Sources
- EDR process creation and network connection logs
- Windows Event Log: Task Scheduler operational channel (Microsoft-Windows-TaskScheduler/Operational)
- Windows Registry Run key monitoring (Sysmon Event ID 13 or equivalent)
- DNS resolution logs
- Web proxy logs with TLS inspection capability
- macOS Unified Log: LaunchAgent loading events
- Linux cron job creation logs
- File system monitoring for node_modules/.cache/ directory creation
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Node.js processes making outbound HTTPS requests to azurewebsites.net subdomains with API paths containing /api/rabbit/, /gate/, /sdk/v2/, or /beacon indicate NodeRabbit or PollCat C2 activity | EDR network connection logs, proxy logs with TLS inspection, DNS resolution logs | Command and Control | Low - legitimate applications rarely use these specific API path patterns on Azure Websites subdomains |
| Scheduled tasks with names containing IntelDriverSupportUpdate, NetSync_, or MicrosoftEdgeUpdate that execute JavaScript files indicate NodeRabbit or PollCat persistence | Windows Task Scheduler operational log, EDR scheduled task creation events | Persistence | Low to Medium - legitimate Intel or Microsoft software may use similar names, but executing .js files through these tasks is unusual |
| Processes binding local TCP listeners on port 48739 or ports in the range 41984-46983, particularly Node.js processes, indicate NodeRabbit single-instance mechanisms | EDR network binding events, host firewall logs, endpoint network connection telemetry | Execution | Low - these specific ports and port ranges are uncommon for legitimate application use |
| Git hook files containing the marker string '# shepherd-persist' or Git hooks that launch Node.js scripts in the background indicate NodeRabbit variant 3 persistence | EDR file monitoring of .git/hooks/ directories, Git audit logs if available | Persistence | Low - this specific marker string is not used by legitimate Git hooks or tooling |
| Renamed Node.js executables such as nodew.exe or IntelDSA.exe with PE subsystem fields modified from Console to GUI indicate NodeRabbit defense evasion | EDR process creation logs with binary metadata, file integrity monitoring for PE header modifications | Defense Evasion | Medium - some legitimate software may rename executables, but PE subsystem modification from Console to GUI is uncommon outside of malware |
Control Gaps
- Cloud-based C2 on Azure Websites subdomains may not be blocked by network firewalls or URL filters because azurewebsites.net is a common legitimate service domain
- Node.js and JavaScript-based malware may not be detected by signature-based antivirus that focuses on native PE binaries
- LinkedIn-based social engineering for initial access bypasses email security gateways and perimeter defenses
- Living-off-the-land use of node.exe, npm, and curl.exe may bypass application allowlisting if these tools are permitted for development
- Trojanized npm packages bundled locally in node_modules directories bypass npm registry scanning and package reputation systems
- Anti-analysis checks in NodeRabbit variant 2 generate benign HEAD requests to google.com, microsoft.com, and cloudflare.com before terminating, which may appear as normal browsing activity
Key Behavioral Indicators
- Node.js processes making HTTPS requests to azurewebsites.net with paths /api/rabbit/, /gate/, /sdk/v2/, or /beacon
- Scheduled tasks named IntelDriverSupportUpdate, NetSync_<username>, or MicrosoftEdgeUpdate executing .js files
- Registry Run key values pointing to .js files executed by renamed node.exe binaries (nodew.exe, IntelDSA.exe)
- Node.js processes binding TCP listeners on port 48739 or ports in the 41984-46983 range
- Git hook files in .git/hooks/post-merge or .git/hooks/post-checkout containing the '# shepherd-persist' marker
- VS Code extension displayed as 'GitHub Copilot Helper' with description 'AI coding assistant helper service' and activation event on StartupFinished
- Renamed node.exe binaries (nodew.exe, IntelDSA.exe) with PE subsystem field changed from Console to Windows GUI
- Node.js processes generating HEAD requests to google.com, microsoft.com, and cloudflare.com before terminating without further C2 contact (anti-analysis behavior in variant 2)
- Files written to %APPDATA%\Microsoft\Network\ or ~/.node_packages/ by npm install commands triggered outside of normal development workflow
- HTTP 400 responses from C2 servers treated as successful registration with socketId extraction from response body
False Positive Assessment
Medium - the malware uses legitimate cloud infrastructure (Azure Websites, Amazon S3) and common developer tools (Node.js, npm) that produce expected activity on developer workstations. Detection based solely on infrastructure connections to azurewebsites.net would generate false positives. Persistence mechanism names (MicrosoftEdgeUpdate, IntelDriverSupportUpdate) could overlap with legitimate software updates. However, the specific C2 API paths, the '# shepherd-persist' Git hook marker, renamed node.exe binaries with PE subsystem modifications, and JavaScript files in Run keys or scheduled tasks provide low false positive detection opportunities.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Search endpoint and network logs for the C2 domains and file hashes listed in this report.
- If any listed C2 domains are observed in network traffic, isolate the affected host and investigate for NodeRabbit or PollCat activity, including persistence mechanisms.
- Check developer workstations for trojanized npm packages named colorized_terminal or pretty-log at version 2.1.0 in local node_modules directories.
- Search for scheduled tasks matching the names IntelDriverSupportUpdate, NetSync_*, or MicrosoftEdgeUpdate that reference .js files or renamed node.exe binaries.
Infrastructure Hardening
- Consider blocking or adding monitoring for the listed Azure Websites C2 subdomains at your web proxy or DNS filter level, where supported by your tooling.
- Evaluate whether outbound traffic to azurewebsites.net subdomains can be restricted or more closely monitored for non-business-essential connections.
- Consider implementing allowlisting for cloud storage providers such as Amazon S3 to prevent automatic execution of downloaded archives without prior scanning.
- If your network security tools support TLS inspection, consider applying it to traffic destined for azurewebsites.net to enable inspection of the C2 API paths.
User Protection
- Consider implementing application control policies that prevent execution of JavaScript files from unexpected locations such as %APPDATA% or ~/.config directories, where supported by your EDR.
- If your EDR supports it, consider adding monitoring for renamed node.exe binaries and PE subsystem field modifications.
- Evaluate whether Git hook files and VS Code extension directories are monitored for unauthorized modifications, if development environments are in scope for your endpoint protection.
- Consider scanning coding challenge archives against the listed file hashes before allowing execution on any managed endpoint.
Security Awareness
- Consider reminding software engineers and hiring managers that coding challenges received from recruiters may contain malware; verify the legitimacy of the recruiter and the organization before running any downloaded code.
- Consider adding guidance to existing security awareness materials about the risk of executing code from unknown or unverified sources, even in the context of job interviews.
- Where applicable, encourage developers to use AI code review tools on coding challenge projects, as the article notes such tools would likely flag the suspicious first-line import of an unknown npm package.
- Consider briefing security teams on the tactic of incorporating targeted organization names into Azure subdomain C2 addresses, which can make malicious traffic appear as normal business activity.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Stealth
Discovery
Collection
Command and Control
Additional IOCs
- Domains:
naturalapplication[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075retaildemo[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075tubitak[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075rgbteller[.]azurewebsites[.]net- NodeRabbit variant 1 C2 fallback server on Azure Websiteswslwebui[.]azurewebsites[.]net- NodeRabbit variant 1 C2 fallback server on Azure Websitescrossdwm[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075wdisystem[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075wslmenus[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075dnshnsdev[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075hpjumpsrv[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075storview[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075kyrasey-f8hfexa5cqamh7fk[.]westeurope-01[.]azurewebsites[.]net- NodeRabbit variant 3 C2 server on Azure West Europe regiongreenyjsgfd[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075helptellerbls[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075timedrv[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075userwellgtfs[.]azurewebsites[.]net- NodeRabbit C2 domain, MarkMonitor-registered, AS 8075hecowime-aqdphyd4bbdef6es[.]westeurope-01[.]azurewebsites[.]net- NodeRabbit C2 domain on Azure West Europe regionmsmanagementgrpmedia[.]com- NodeRabbit variant 7 C2 domain, MarkMonitor-registered, AS 8075gamebarapp[.]azurewebsites[.]net- PollCat C2 server on Azure Websites, MarkMonitor-registeredgamebarappinformation[.]azurewebsites[.]net- PollCat C2 server on Azure Websites, MarkMonitor-registeredhealthful-hub[.]com- Mirage Kitten infrastructure domain, registered 2026-07-03 via NameCheapneumedicahealthcare[.]com- Mirage Kitten infrastructure domain, registered 2026-07-03 via NameCheapoptimumhealthcredit[.]com- Mirage Kitten infrastructure domain, registered 2026-07-03 via NameCheaphealthfullyrecipes[.]com- Mirage Kitten infrastructure domain, registered 2026-06-30 via NameCheaprefreshhealthandwellness[.]com- Mirage Kitten infrastructure domain, registered 2026-06-09 via NameCheaphealthvitalitycare[.]com- Mirage Kitten infrastructure domain, registered 2026-05-18 via NameCheapaceofspadesmanagement[.]com- Mirage Kitten infrastructure domain, registered 2026-05-18 via NameCheapglmediaagency[.]com- Mirage Kitten infrastructure domain, registered 2026-05-18 via NameCheapdigimediaskill[.]com- Mirage Kitten infrastructure domain, registered 2026-05-18 via NameCheaphealthyweightplan[.]com- Mirage Kitten infrastructure domain, registered 2026-05-18 via NameCheapmens-health-online[.]com- Mirage Kitten infrastructure domain, registered 2026-05-15 via NameCheap
- Urls:
hxxps://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate- PollCat OTP validation endpoint on attacker-managed domain; application forwards submitted OTP codes here during the fake coding assessment
- File Hashes:
CBAAF0900A13F28E380F49ADECEC932C(MD5) - MD5 hash of FrontEnd-Task.zip, a trojanized coding challenge archive366515822D5AC1CC500711EF57A2E32E(MD5) - MD5 hash of Task-FullStack.zip, a trojanized coding challenge archiveCF449F1992C2819E62AC44A0B06AC2E7(MD5) - MD5 hash of fullstack-1536.zip, a trojanized coding challenge archiveE95A4366686E3F786EA3C056FAB5B0DA(MD5) - MD5 hash of webapp76592.zip, a trojanized coding challenge archiveDE5AF16A3757EF700B01DC34D67079AE(MD5) - MD5 hash of webapp76531.zip, a trojanized coding challenge archiveBE086789568441D0D7E4679AEE51F566(MD5) - MD5 hash of challenges-17831.zip, a trojanized coding challenge archiveE259C5EDF158AAC4CFE14F77DDD0B196(MD5) - MD5 hash of challenges-17832.zip, a trojanized coding challenge archive291AC3ABE73C5158E59A437B75D5F0AA(MD5) - MD5 hash of Project-1802.zip, a trojanized coding challenge archive0962F56D7EC69F4F2A0162DCBE22116B(MD5) - MD5 hash of Case-34234.zip, a trojanized coding challenge archive810F8E3B88EB05F710C09552941D6F56(MD5) - MD5 hash of the Retrograde/MiniFast native DLL backdoor, used for attribution to Mirage Kitten based on shared C2 protocol structure
- Registry Keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftEdgeUpdate- NodeRabbit variant 1 Windows persistence Run key, executes nodew.exe with msedge_update.js payloadHKCU\Software\Microsoft\Windows\CurrentVersion\Run- NodeRabbit variant 3 uses this Run key for persistence via fake VS Code extension when extension directory is missing on Windows
- File Paths:
node_modules/.cache/.320697f1/index.js- Hidden NodeRabbit payload location in trojanized coding challenge project, launched by colorized_terminal npm package as detached background process%APPDATA%\Microsoft\EdgeUpdate\msedge_update.js- NodeRabbit variant 1 Windows persistence payload copy%LOCALAPPDATA%\Intel\DSA\idriver_support.js- NodeRabbit variant 2 Windows persistence payload, masquerading as Intel Driver and Support Assistant%APPDATA%\Microsoft\Network- PollCat Windows persistence directory where package.json and requireObject.js are written~/Library/LaunchAgents/com.microsoft.edgeupdate.plist- NodeRabbit variant 1 macOS persistence LaunchAgent with RunAtLoad and KeepAlive parameters~/Library/LaunchAgents/com.intel.dsa.helper- NodeRabbit variant 2 macOS persistence LaunchAgent~/Library/LaunchAgents/com.harsh.requireobject.plist- PollCat macOS persistence LaunchAgent with RunAtLoad and daily 09AM trigger.sv.json- NodeRabbit variant 3 C2 configuration file written by agent:servers command to persist updated C2 server list
- Command Lines:
- Purpose: Initial execution of PollCat RAT when victim runs the trojanized coding challenge project | Tools:
npm,node| Stage: Execution |npm i && node index.js - Purpose: NodeRabbit variant 1 Windows persistence execution via renamed node.exe | Tools:
nodew.exe| Stage: Persistence |nodew.exe msedge_update.js - Purpose: NodeRabbit variant 2 Windows persistence via scheduled task executing renamed node.exe with payload script | Tools:
IntelDSA.exe| Stage: Persistence |IntelDSA.exe <script>.js - Purpose: NodeRabbit variant 2 corporate proxy NTLM/Negotiate authentication delegation for C2 traffic | Tools:
curl.exe| Stage: C2 |curl.exe --proxy-anyauth --proxy-user - Purpose: NodeRabbit variant 3 Windows persistence via scheduled task creation | Tools:
schtasks| Stage: Persistence |schtasks /create /tn <taskname> /tr - Purpose: PollCat Windows persistence via scheduled task creation with daily trigger | Tools:
schtasks| Stage: Persistence |schtasks /create /tn NetSync_<username> - Purpose: NodeRabbit variant 3 WSL persistence via VBScript launcher and Windows scheduled task | Tools:
wscript.exe,wsl.exe| Stage: Persistence |wscript.exe launcher.vbs
- Purpose: Initial execution of PollCat RAT when victim runs the trojanized coding challenge project | Tools:
- Other:
[email protected]- Trojanized npm package version used by NodeRabbit variants 1 and 2, bundled locally in node_modules rather than published to npm registry[email protected]- Trojanized npm package version used by NodeRabbit variants 2 and 3, bundled locally in coding challenge archivesGitHub Copilot Helper- Fake VS Code extension name used by NodeRabbit variant 3 persist:vscode command, displayed with description 'AI coding assistant helper service' and activation event on StartupFinished# shepherd-persist;- Marker string appended to .git/hooks/post-merge and .git/hooks/post-checkout by NodeRabbit variant 3 Git hook injection persistence