Iran-linked APT Mirage Kitten Uses Fake Job Tests to Spread Malware

September 2, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: securityaffairs.com

Threat Risk: High
Victim: Software engineers in the Middle East and Africa
Incident: Deployment of trojanized coding challenges to compromise developer workstations.
Impact: Unauthorized access to sensitive engineering environments and potential for wide-scale cyberespionage.
Attacker: Mirage Kitten
Analysis: Mirage Kitten is targeting software engineers through fraudulent LinkedIn recruitment and fake coding assessments. By explicitly prohibiting AI assistants during the test, the attackers prevent automated code reviews from flagging trojanized npm packages. The cross-platform NodeRabbit malware utilizes sophisticated anti-analysis techniques and encrypted C2 communications to maintain stealth.
Recommendations: Verify recruiter identities and job offers through official corporate channels before downloading files.; Execute all external coding assessments within isolated sandboxes or virtual machines.; Use security-focused static analysis tools to audit third-party code regardless of test instructions.
Source: Security Affairs

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *