Kaspersky identified NodeRabbit and PollCat, two previously undocumented cross-platform remote access trojans deployed by the Mirage Kitten APT group. NodeRabbit is a Node.js RAT delivered through trojanized coding challenge archives on job search platforms, communicating with Azure-hosted C2 endpoints using AES-256-GCM encryption. PollCat is an obfuscated JavaScript RAT using HTTP polling with a custom C2 protocol that treats HTTP 400 responses as successful registration and shares structural similarities with the Retrograde/MiniFast backdoor. Both malware families target Windows, Linux, and macOS, with NodeRabbit variant 3 introducing persistence via fake VS Code extensions and Git hook injection.
NodeRabbit
1 post
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set