ICNA

Iranian Cyber News Agency

Attack Cyber Hack

Iranian Hackers and a New Fake Job Recruitment Campaign

According to Russian cybersecurity firm Kaspersky, the hacking group Nimbus Manticore (also known as Mirage Kitten) is conducting a malware campaign targeting software developers and other technical experts in Afghanistan, Ethiopia, and Egypt by offering fake jobs on job platforms such as LinkedIn. The attackers pose as recruiters and hide malicious code within coding challenges. The group exploited NodeRabbit and PollCat – two previously unseen malware families.

The Iranian hacking group, “Mirage Kitten”, which is attributed to the Islamic Republic of Iran, has launched a new campaign. The group previously gained notoriety for its “Iranian Dream Job” campaign. Last year, in this campaign, the group targeted aerospace and technology industries in Europe by offering fake jobs. During this attack, victims downloaded malicious files after being directed to a fake employment website.

For more information about this group and their activities, visit our Cyber Actors section.

In this campaign, two malware programs are presented as programming tests and technical employment assessments, leading victims to believe that they are engaged in a normal hiring process. The first discovered malware is named Node Rabbit, with its first instance seen in Afghanistan and subsequent instances in Egypt and Ethiopia. The malware is developed using Node.js and Javascript and provides a cross-platform attack base. NodeRabbit runs as a hidden process in the background via manipulated npm packages.

The second malware identified in this campaign is PollCat, built on obfuscated Javascript and its project containing indicators and terminology from CTF (Capture the Flag) challenges. This malware may have been generated by artificial intelligence. It misleads users by requesting one-time password (OTP) login forms, but its malicious function doesn’t depend on the correctness of the code and remains active on the system even if the validation fails.

Recent activities of Mirage Kitten show they are trending towards scripting to infect Windows, Linux, and Mac operating systems simultaneously with one codebase. The group’s new cyber tools showcase that Mirage Kitten is significantly enhancing its malware capabilities.

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *