Advisory
Published 2026-09-01
Verified 2026-09-19

Kaspersky: Mirage Kitten (Nimbus Manticore) ships NodeRabbit and PollCat RATs

Kaspersky Securelist published on 1 September 2026 that Iranian APT Mirage Kitten (also tracked as Nimbus Manticore, UNC1549, Smoke Sandstorm) is using two previously undocumented cross-platform RATs: NodeRabbit (Node.js) and PollCat (obfuscated JavaScript), the first publicly documented Node.js and JavaScript malware from this group. Operators deliver the implants through recruiter personas on LinkedIn and other job platforms, using trojanized coding-challenge archives. Kaspersky found NodeRabbit samples on systems in Afghanistan, Egypt and Ethiopia. PollCat was recovered from a RankChallenge-react assessment archive. The group has historically used C, C++ and Go malware against aviation, aerospace and fintech in the Middle East and Africa. Kaspersky detections: Trojan.JS.MirageKitten.*.

Product
n/a (developer workstations; Windows, Linux, macOS)
Exploited in Australia?
unknown
Patch to
Treat unsolicited recruiter coding-challenge archives as untrusted

Primary: Kaspersky Securelist (1 Sep 2026) ยท The Hacker News (1 Sep 2026)

tech