type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, espionage, rat, supply-chain, aviation, iran] ยท confidence: high ยท severity: high ยท affected_sectors: [defence, finance, aviation] ยท au_impact: true
Iranian Mirage Kitten Targets Aviation and Fintech Developers With NodeRabbit and PollCat
Summary
Kaspersky documented Iran-linked espionage group Mirage Kitten (also tracked as UNC1549, Smoke Sandstorm, Nimbus Manticore) targeting developers and specialists in aviation, aerospace and financial-technology in Egypt, Ethiopia and Afghanistan through fake job offers on LinkedIn and other platforms.
Key Facts
- Delivery: Trojanised coding challenges sent as fake job offers; victims receive malware masquerading as a legitimate task.
- Malware: Two previously undocumented families โ NodeRabbit, a Node.js-based cross-platform RAT for Windows, Linux and macOS, and PollCat, an obfuscated JavaScript RAT. Tests banned AI assistants, possibly to keep automated tools from flagging embedded malicious code.
- Infrastructure: Abrades legitimate Microsoft Azure and Cloudflare infrastructure, at times naming Azure subdomains after targeted organisations.
- New capability: First documented Node.js/JavaScript malware by the group, which historically used C, C++ and Go.
Significance
State-sponsored espionage prioritising trusted-path collection and developer supply-chain footholds is directly relevant to the developer supply chain of Australian and NZ aviation, aerospace and fintech firms.