[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fEzNe9KwUZz35SXozz1-pv6h6r_j99SnmaOriuVEe6tA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"5ca9f3e0-b3ce-467d-992d-84890c23eaf2","apt-group-mirage-kitten-uses-trojanized-coding-challenges-to-deploy-novel-rats","80d608c4-4fe1-4042-b9e0-84d2d42db47a","APT Group Mirage Kitten Uses Trojanized Coding Challenges to Deploy Novel RATs","Mirage Kitten is leveraging spear-phishing campaigns disguised as legitimate coding challenges to deliver two previously unknown cross-platform remote access trojans, NodeRabbit and PollCat, targeting aviation and FinTech organizations across the Middle East and Africa. The use of trojanized archives exploits the trust professionals place in routine recruitment or skills-assessment workflows, making detection more difficult and social engineering more effective. The shift to Node.js and JavaScript-based malware broadens the attack surface to multiple operating systems, bypassing defenses tuned for traditional native malware signatures. This campaign highlights how advanced threat actors continuously evolve their tooling and delivery mechanisms to outpace organizational defenses and threat intelligence.","**Immediate actions:**\n- Block execution of scripting runtimes (Node.js, JavaScript engines) from untrusted or unsanctioned sources via application allowlisting.\n- Implement email filtering rules to quarantine and inspect compressed archives and executable attachments, especially those mimicking coding challenge or recruitment materials.\n- Issue an urgent advisory to staff in aviation and FinTech roles warning them not to execute unsolicited code archives or run coding exercises from unknown senders.\n\n**Long-term improvements:**\n- Establish a formal vendor and recruitment workflow verification process to authenticate the source of any coding assessments or technical exercises before execution.\n- Deploy endpoint detection and response (EDR) solutions capable of detecting anomalous Node.js or JavaScript process behavior and lateral movement.\n- Conduct regular, role-specific phishing simulations targeting technical staff who are likely recipients of credential- or career-themed lures.\n\n**Detection measures:**\n- Monitor network egress for outbound connections initiated by scripting runtimes (node.exe, wscript.exe) to unfamiliar or newly registered domains.\n- Correlate SIEM alerts on archive extraction events followed immediately by script interpreter execution as a high-fidelity detection rule.\n- Subscribe to threat intelligence feeds covering APT groups active in the Middle East and Africa to receive timely indicators of compromise for Mirage Kitten tooling.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","CIS Control 13: Network Monitoring and Defense","NIST SP 800-61: Incident Handling Guide","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SA-8: Security and Privacy Engineering Principles","NIST SP 800-53 AT-2: Literacy Training and Awareness","MITRE ATT&CK T1566.001: Spearphishing Attachment","MITRE ATT&CK T1059.007: JavaScript Execution","MITRE ATT&CK T1027: Obfuscated Files or Information","ISO\u002FIEC 27001 A.12.2: Protection from Malware","published","2026-09-01T08:21:27.796651+00:00","2026-09-01T08:21:27.705+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fsecurelist.com\u002Fmirage-kitten-new-backdoors-noderabbit-pollcat\u002F121244\u002F","mirage-kitten-targeting-aviation-and-fintech-sectors-across-the-middle-east-and--eac188","Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]