Kaspersky identified NodeRabbit and PollCat, two previously undocumented cross-platform remote access trojans deployed by the Mirage Kitten APT group. NodeRabbit is a Node.js RAT delivered through trojanized coding challenge archives on job search platforms, communicating with Azure-hosted C2 endpoints using AES-256-GCM encryption. PollCat is an obfuscated JavaScript RAT using HTTP polling with a custom C2 protocol that treats HTTP 400 responses as successful registration and shares structural similarities with the Retrograde/MiniFast backdoor. Both malware families target Windows, Linux, and macOS, with NodeRabbit variant 3 introducing persistence via fake VS Code extensions and Git hook injection.
Mirage Kitten
2 posts
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set Mirage Kitten targets Middle East and Africa region with new malware Mirage Kitten has expanded its malware arsenal with NightLedger, a Windows backdoor abusing DLL search-order hijacking via a malicious SspiCli.dll, and two WebSocket-based tunneling tools (ArcBridge and BridgeHead) that establish SOCKS5 proxy relays through victim networks. The tools employ anti-analysis techniques such as username-substring checks, enterprise proxy traversal with NTLM/Negotiate authentication, and a shift from Azure-hosted to Cloudflare-backed C2 infrastructure to complicate attribution.