Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set


While monitoring Mirage Kitten activity, Kaspersky researchers uncovered a previously undocumented malware family that we dubbed NodeRabbit. The researchers identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia.

NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives.

During the same investigation, the researchers discovered another previously undocumented malware family that we dubbed PollCat. Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives.

Read more…
Source:  Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • New Android malware lets criminals use your bank card in real time

    August 13, 2026

    Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, ...

  • Armored Likho expands its cyber-espionage toolkit

    August 13, 2026

    In May 2026, Kaspersky researches discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, ...

  • Uber Freight reportedly investigating after hacking group claims data breach

    August 12, 2026

    A hacking and extortion gang has taken credit for a cyberattack and data breach at Uber Freight, the ridesharing giant’s logistics subsidiary. A spokesperson for Uber Freight told Reuters, which first reported the incident, that there was no effect on its business operations and that its systems were running normally. (The company did not immediately respond to ...

  • Fake CCleaner installs GhostDesk Chrome spyware

    August 11, 2026

    A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk, which acts as spyware inside the browser. With more than 2 billion downloads worldwide, CCleaner is one of the best-known Windows utilities, making it an attractive target for cybercriminals looking to distribute ...

  • UK MoD says no data leaked to China via drone vulnerability

    August 10, 2026

    Britain’s Ministry of Defence said on Monday that there is no evidence that military data was compromised after a cyber vulnerability was discovered in Royal Navy drones. The issue was identified during routine cybersecurity testing, the ministry said, adding that it continues to conduct security checks across its equipment and systems. Read more… Source:  EUROACTIV Sign up for the ...

  • StopRansomware: Gunra Ransomware

    August 10, 2026

    Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom ...