Iran-linked Mirage Kitten targets developers with fake job malware
An Iran-linked hacking group known as Mirage Kitten has launched a sophisticated cyberespionage campaign targeting software developers in the aviation, fintech, and aerospace sectors across the Middle East and Africa. The operation, detailed in research published on September 1, 2026, involves fake job recruitment lures on LinkedIn that deliver two previously undocumented cross-platform malware families, NodeRabbit and PollCat. The attack chain begins with threat actors posing as recruiters from major technology companies. They contact software engineers on professional networking platforms and invite them to complete a technical assessment as part of a hiring process. Victims are directed to download a coding challenge hosted on legitimate Amazon cloud storage. The archives contain a project with a strict time limit, often one to three hours, and explicit instructions not to use AI code-assistance tools. Researchers noted this rule appears designed to prevent the very tools most likely to flag the malicious code hidden within the project. Once a developer downloads and runs the coding challenge, the malware installs itself in the background.