Threat reportMalwareTL-2026-3061

Malware-as-a-Service (MaaS) Ecosystem Overview, Including Nimbus Manticore (Mirage Kitten) NodeRabbit and PollCat Fake-Recruitment Campaign

highACTIVE

Malware-as-a-Service (MaaS) Ecosystem Overview, Including (TL-2026-3061), also tracked as NodeRabbit, is a high-severity malware campaign, first published 2026-10-08. It is attributed to UNC1549 (Iran) with high confidence, affects Node.js / npm ecosystem Developer workstations running untrusted, maps to 18 MITRE ATT&CK techniques (T1036.005, T1053.003, T1053.005), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
2UNC1549
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-3061

Threat ID
TL-2026-3061
Also known as
NodeRabbit, PollCat, Trojan.JS.MirageKitten
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC1549, Mirage Kitten
Attribution confidence
HIGH
Nation-state nexus
Iran
Motivation
ESPIONAGE
Target sectors
aviation, aerospace, fintech, software-development
Target regions
Middle East, Africa, afghanistan, egypt, ethiopia
Detection rules
9
Indicators of compromise
28

How Malware-as-a-Service (MaaS) Ecosystem Overview, Including works

DarkOwl's MaaS primer cites the Iranian group Nimbus Manticore (Mirage Kitten, 'Iranian Dream Job'), which uses fake-recruiter coding challenges to deliver two previously undocumented Node.js RATs, NodeRabbit and PollCat. Kaspersky's Securelist research attributes the activity with high confidence and confirmed victims in aviation/aerospace and fintech in Afghanistan, Egypt and Ethiopia.

DarkOwl (2026-10-08) explains the Malware-as-a-Service model in which developers build, market and lease malware and supporting infrastructure (infostealers, RATs, botnet malware, ransomware) to other actors. The six stages it describes are development, distribution/marketing, purchase/subscription, deployment, collection/monetization, and resale/further exploitation. The article is largely educational and lists no IOCs; its case study is Nimbus Manticore, a state-linked actor rather than a pure MaaS vendor.

The underlying research is Kaspersky's Securelist report 'Mirage Kitten: new backdoors NodeRabbit and PollCat' (2026-09-01, Omar Amin). A fake talent-acquisition persona contacts developers on LinkedIn and other job platforms and sends a link to a time-limited coding assessment hosted in an Amazon S3 bucket (oracle-challenge, us-east-1). The README imposes a three-hour limit, bans AI assistants, and claims the server component is already bug-free. In the TaskFlow lure, server.js imports a trojanized package, colorized_terminal 2.1.0 or pretty-log 2.1.0, bundled inside node_modules (not published on npm). The package launches an implant from node_modules/.cache/<hex>/index.js as a detached process. Variants were found in Afghanistan (first sample, a software engineer), Egypt and Ethiopia.

NodeRabbit is a cross-platform (Windows, Linux, macOS) Node.js RAT. C2 requests are JSON encrypted with AES-256-GCM (key = SHA-256 of an embedded seed) and sent to Azure App Service hosts with failover. Variant 1 has 11 commands (sys:info, proc:list, fs:read/write/delete, script:exec and others) and persists as a fake Microsoft Edge update. Variant 2 adds anti-analysis checks (low RAM/CPU, short uptime, analyst usernames or tools), corporate proxy support (including NTLM/Negotiate via curl.exe) and masquerades as 'Intel Driver & Support Assistant'. Variant 3 uses /sdk/v2/* endpoints, adds 12 commands including Outlook OST/PST address harvesting, a fake VS Code extension ('GitHub Copilot Helper'), Git-hook injection (post-merge/post-checkout marked '# shepherd-persist') and WSL-based persistence.

PollCat is a second, obfuscated JavaScript RAT delivered in a React lure (RankChallenge-react, run via 'npm i && node index.js') that asks for a recruiter-supplied six-digit OTP validated against lifespotify.com. The implant registers with C2 before OTP entry, so a failed OTP does not stop it. It polls every 2 minutes with up to 5 s jitter, declares 22 commands (RUN, RUN_HIDDEN, EVAL_JS, UPLOAD, DOWNLOAD, ZIP, RUNDLL and others; WS_DOWNLOAD, REQUEST_ELEVATION and PERSIST are unimplemented) and enumerates 24 security/software-vendor folders. Kaspersky links both to Mirage Kitten's Retrograde/MiniFast backdoor through the shared HTTP 400 socketId handshake, identical timing defaults, shared command IDs, victimology and Azure/Cloudflare infrastructure.

Note: DarkOwl describes NodeRabbit as targeting Linux and macOS; Kaspersky documents Windows, Linux and macOS variants. Kaspersky also suggests the lure projects may be AI-assisted or template-generated. Browser-credential theft is not described in the Securelist-derived sources.

MITRE ATT&CK techniques used in TL-2026-3061

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1497.001 System Checks

Persistence

T1053.003 Cron; T1053.005 Scheduled Task; T1543.001 Launch Agent; T1546 Event Triggered Execution; T1547.001 Registry Run Keys / Startup Folder

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

Execution

T1059.007 JavaScript; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1573.001 Symmetric Cryptography

Collection

T1114.001 Local Email Collection

Initial Access

T1566.003 Spearphishing via Service

Resource Development

T1583.006 Web Services; T1585.001 Social Media Accounts

Affected products and versions in Malware-as-a-Service (MaaS) Ecosystem Overview, Including

  • Node.js / npm ecosystem — Developer workstations running untrusted Node.js projects (Windows, Linux, macOS)
    Vulnerable versions: colorized_terminal 2.1.0 (trojanized, bundled in lure archives); pretty-log 2.1.0 (trojanized, bundled in lure archives)

Remediation for Malware-as-a-Service (MaaS) Ecosystem Overview, Including

Immediate actions

  • Block the listed Azure App Service, custom C2 and OTP domains at DNS/proxy and alert on historical hits
  • Hunt endpoints for node_modules/.cache/<hex>/index.js, colorized_terminal 2.1.0 and pretty-log 2.1.0, and for the listed persistence artifacts (IntelDriverSupportUpdate task, MicrosoftEdgeUpdate Run value, com.microsoft.edgeupdate / com.intel.dsa.helper LaunchAgents, '# shepherd-persist' in .git/hooks)
  • Rotate cloud credentials, tokens and secrets on any machine that ran an unsolicited coding challenge

Workarounds

  • Inspect server.js and startup files before running any received project; review dependencies bundled in node_modules
  • Remove unexpected VS Code extensions and re-enable Workspace Trust

Longer-term hardening

  • Run third-party coding assessments only in isolated VMs/containers without production credentials or source access
  • Deploy EDR with behavioral detection for detached Node.js children, Node.js persistence creation and Git-hook modification
  • Train developers to verify recruiters through the employer's official channel
  • Restrict network egress to *.azurewebsites.net from developer workstations where feasible

Timeline of Malware-as-a-Service (MaaS) Ecosystem Overview, Including

  • Start of the window (15 May to 3 Jul 2026) in which Mirage Kitten registered the campaign domains; lifespotify.com was registered in late June 2026
  • End of the domain-registration window observed by Kaspersky for the NodeRabbit/PollCat infrastructure
  • The Hacker News and Cyber Security News/Cryptika report the fake-recruiter coding-test campaign targeting developers
  • Kaspersky attributes the malware to Mirage Kitten (Nimbus Manticore) with high confidence via shared handshake, command IDs, timing defaults and infrastructure overlap with Retrograde/MiniFast
  • Kaspersky (Omar Amin) publishes 'Mirage Kitten: new backdoors NodeRabbit and PollCat' on Securelist, documenting three NodeRabbit variants (Afghanistan, Egypt, Ethiopia) and PollCat
  • DarkOwl publishes 'What is Malware as a Service?', using Nimbus Manticore's NodeRabbit/PollCat campaign as a case study

Sources cited for Malware-as-a-Service (MaaS) Ecosystem Overview, Including

Detection coverage for TL-2026-3061

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3061 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats