Switches to Node.js and JavaScript malware
Mirage Kitten, an APT group historically focused on the Middle East and Africa, has deployed two previously undocumented cross-platform remote access trojans: NodeRabbit (Node.js-based) and PollCat (JavaScript-based). Both malware families mark the group's first departure from native malware toward scripting languages compatible with Windows, Linux, and macOS. Operators deliver these tools through sophisticated social engineering campaigns involving fake recruiters on LinkedIn who distribute trojanized coding challenges via Amazon S3 buckets. The malicious projects contain backdoored npm packages that silently install persistent implants. NodeRabbit implements comprehensive command-and-control capabilities including file operations, process management, and proxy-aware C2 communications through Azure and Cloudflare infrastructure. PollCat provides similar RAT functionality with specialized developer persistence mechanisms targeting VS Code extensions and Git hooks. Targeted sectors include aviation, aerospa...
Indicators of Compromise
- domain: msmanagementgrp.com
- hash: 810f8e3b88eb05f710c09552941d6f56
- hash: da11679653ef33952c3dc8d8850e43d7b8ac884a
- hash: 0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864
- domain: sahi-finance.com
- domain: healthcomfsdpower.com
- domain: visitfinancedentists.com
- domain: optimumhealthcredit.com
- hash: 1ea83e4e4592b01e4acab63eb867bee5
- hash: cbaaf0900a13f28e380f49adecec932c
- hash: 366515822d5ac1cc500711ef57a2e32e
- hash: cf449f1992c2819e62ac44a0b06ac2e7
- hash: e95a4366686e3f786ea3c056fab5b0da
- hash: de5af16a3757ef700b01dc34d67079ae
- hash: be086789568441d0d7e4679aee51f566
- hash: e259c5edf158aac4cfe14f77ddd0b196
- hash: 291ac3abe73c5158e59a437b75d5f0aa
- hash: 0962f56d7ec69f4f2a0162dcbe22116b
- hash: 795e053a990a1569ffdcb57f48f6d085
- url: https://lifespotify.com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate
- domain: lifespotify.com
- domain: msmanagementgrpmedia.com
- domain: healthful-hub.com
- domain: neumedicahealthcare.com
- domain: healthfullyrecipes.com
- domain: refreshhealthandwellness.com
- domain: healthvitalitycare.com
- domain: aceofspadesmanagement.com
- domain: glmediaagency.com
- domain: digimediaskill.com
- domain: healthyweightplan.com
- domain: mens-health-online.com
- url: https://visitfinancedentists.com
- url: https://healthcomfsdpower.com
- url: https://sahi-finance.com
- hash: f0c8db403231d478f67df0355328c58384027677
- hash: 307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00
Switches to Node.js and JavaScript malware
Description
Mirage Kitten, an APT group historically focused on the Middle East and Africa, has deployed two previously undocumented cross-platform remote access trojans: NodeRabbit (Node.js-based) and PollCat (JavaScript-based). Both malware families mark the group's first departure from native malware toward scripting languages compatible with Windows, Linux, and macOS. Operators deliver these tools through sophisticated social engineering campaigns involving fake recruiters on LinkedIn who distribute trojanized coding challenges via Amazon S3 buckets. The malicious projects contain backdoored npm packages that silently install persistent implants. NodeRabbit implements comprehensive command-and-control capabilities including file operations, process management, and proxy-aware C2 communications through Azure and Cloudflare infrastructure. PollCat provides similar RAT functionality with specialized developer persistence mechanisms targeting VS Code extensions and Git hooks. Targeted sectors include aviation, aerospa...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/"]
- Adversary
- Mirage Kitten
- Pulse Id
- 6a96918b7f129c94fa473bb0
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainmsmanagementgrp.com | — | |
domainsahi-finance.com | — | |
domainhealthcomfsdpower.com | — | |
domainvisitfinancedentists.com | — | |
domainoptimumhealthcredit.com | — | |
domainlifespotify.com | — | |
domainmsmanagementgrpmedia.com | — | |
domainhealthful-hub.com | — | |
domainneumedicahealthcare.com | — | |
domainhealthfullyrecipes.com | — | |
domainrefreshhealthandwellness.com | — | |
domainhealthvitalitycare.com | — | |
domainaceofspadesmanagement.com | — | |
domainglmediaagency.com | — | |
domaindigimediaskill.com | — | |
domainhealthyweightplan.com | — | |
domainmens-health-online.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash810f8e3b88eb05f710c09552941d6f56 | — | |
hashda11679653ef33952c3dc8d8850e43d7b8ac884a | — | |
hash0db36a04d304ad96f9e6f97b531934594cd95a5cea9ff2c9af249201089dc864 | — | |
hash1ea83e4e4592b01e4acab63eb867bee5 | — | |
hashcbaaf0900a13f28e380f49adecec932c | — | |
hash366515822d5ac1cc500711ef57a2e32e | — | |
hashcf449f1992c2819e62ac44a0b06ac2e7 | — | |
hashe95a4366686e3f786ea3c056fab5b0da | — | |
hashde5af16a3757ef700b01dc34d67079ae | — | |
hashbe086789568441d0d7e4679aee51f566 | — | |
hashe259c5edf158aac4cfe14f77ddd0b196 | — | |
hash291ac3abe73c5158e59a437b75d5f0aa | — | |
hash0962f56d7ec69f4f2a0162dcbe22116b | — | |
hash795e053a990a1569ffdcb57f48f6d085 | — | |
hashf0c8db403231d478f67df0355328c58384027677 | — | |
hash307ce2448211a5f5d122643f2a739aff33ede72c1858518c8de098f3148bbd00 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://lifespotify.com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate | — | |
urlhttps://visitfinancedentists.com | — | |
urlhttps://healthcomfsdpower.com | — | |
urlhttps://sahi-finance.com | — |
Threat ID: 6a96dc1eacd9273b49cad39e
Added to database: 09/01/2026, 14:07:26 UTC
Last updated: 09/01/2026, 21:42:54 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.