Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Switches to Node.js and JavaScript malware

0
Medium
Published: 09/01/2026 (09/01/2026, 08:49:15 UTC)
Source: AlienVault OTX General

Description

Mirage Kitten, an APT group historically focused on the Middle East and Africa, has deployed two previously undocumented cross-platform remote access trojans: NodeRabbit (Node.js-based) and PollCat (JavaScript-based). Both malware families mark the group's first departure from native malware toward scripting languages compatible with Windows, Linux, and macOS. Operators deliver these tools through sophisticated social engineering campaigns involving fake recruiters on LinkedIn who distribute trojanized coding challenges via Amazon S3 buckets. The malicious projects contain backdoored npm packages that silently install persistent implants. NodeRabbit implements comprehensive command-and-control capabilities including file operations, process management, and proxy-aware C2 communications through Azure and Cloudflare infrastructure. PollCat provides similar RAT functionality with specialized developer persistence mechanisms targeting VS Code extensions and Git hooks. Targeted sectors include aviation, aerospa...

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/"]
Adversary
Mirage Kitten
Pulse Id
6a96918b7f129c94fa473bb0
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainmsmanagementgrp.com
domainsahi-finance.com
domainhealthcomfsdpower.com
domainvisitfinancedentists.com
domainoptimumhealthcredit.com
domainlifespotify.com
domainmsmanagementgrpmedia.com
domainhealthful-hub.com
domainneumedicahealthcare.com
domainhealthfullyrecipes.com
domainrefreshhealthandwellness.com
domainhealthvitalitycare.com
domainaceofspadesmanagement.com
domainglmediaagency.com
domaindigimediaskill.com
domainhealthyweightplan.com
domainmens-health-online.com

Hash

ValueDescriptionCopy
hash810f8e3b88eb05f710c09552941d6f56
hashda11679653ef33952c3dc8d8850e43d7b8ac884a
hash0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864
hash1ea83e4e4592b01e4acab63eb867bee5
hashcbaaf0900a13f28e380f49adecec932c
hash366515822d5ac1cc500711ef57a2e32e
hashcf449f1992c2819e62ac44a0b06ac2e7
hashe95a4366686e3f786ea3c056fab5b0da
hashde5af16a3757ef700b01dc34d67079ae
hashbe086789568441d0d7e4679aee51f566
hashe259c5edf158aac4cfe14f77ddd0b196
hash291ac3abe73c5158e59a437b75d5f0aa
hash0962f56d7ec69f4f2a0162dcbe22116b
hash795e053a990a1569ffdcb57f48f6d085
hashf0c8db403231d478f67df0355328c58384027677
hash307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00

Url

ValueDescriptionCopy
urlhttps://lifespotify.com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate
urlhttps://visitfinancedentists.com
urlhttps://healthcomfsdpower.com
urlhttps://sahi-finance.com

Threat ID: 6a96dc1eacd9273b49cad39e

Added to database: 09/01/2026, 14:07:26 UTC

Last updated: 09/01/2026, 21:42:54 UTC

Views: 16

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses