Threat reportMalwareTL-2026-3061
Malware-as-a-Service (MaaS) Ecosystem Overview, Including Nimbus Manticore (Mirage Kitten) NodeRabbit and PollCat Fake-Recruitment Campaign
Malware-as-a-Service (MaaS) Ecosystem Overview, Including (TL-2026-3061), also tracked as NodeRabbit, is a high-severity malware campaign, first published 2026-10-08. It is attributed to UNC1549 (Iran) with high confidence, affects Node.js / npm ecosystem Developer workstations running untrusted, maps to 18 MITRE ATT&CK techniques (T1036.005, T1053.003, T1053.005), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 2UNC1549
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-3061
- Threat ID
- TL-2026-3061
- Also known as
- NodeRabbit, PollCat, Trojan.JS.MirageKitten
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UNC1549, Mirage Kitten
- Attribution confidence
- HIGH
- Nation-state nexus
- Iran
- Motivation
- ESPIONAGE
- Target sectors
- aviation, aerospace, fintech, software-development
- Target regions
- Middle East, Africa, afghanistan, egypt, ethiopia
- Detection rules
- 9
- Indicators of compromise
- 28
How Malware-as-a-Service (MaaS) Ecosystem Overview, Including works
DarkOwl's MaaS primer cites the Iranian group Nimbus Manticore (Mirage Kitten, 'Iranian Dream Job'), which uses fake-recruiter coding challenges to deliver two previously undocumented Node.js RATs, NodeRabbit and PollCat. Kaspersky's Securelist research attributes the activity with high confidence and confirmed victims in aviation/aerospace and fintech in Afghanistan, Egypt and Ethiopia.
DarkOwl (2026-10-08) explains the Malware-as-a-Service model in which developers build, market and lease malware and supporting infrastructure (infostealers, RATs, botnet malware, ransomware) to other actors. The six stages it describes are development, distribution/marketing, purchase/subscription, deployment, collection/monetization, and resale/further exploitation. The article is largely educational and lists no IOCs; its case study is Nimbus Manticore, a state-linked actor rather than a pure MaaS vendor.
The underlying research is Kaspersky's Securelist report 'Mirage Kitten: new backdoors NodeRabbit and PollCat' (2026-09-01, Omar Amin). A fake talent-acquisition persona contacts developers on LinkedIn and other job platforms and sends a link to a time-limited coding assessment hosted in an Amazon S3 bucket (oracle-challenge, us-east-1). The README imposes a three-hour limit, bans AI assistants, and claims the server component is already bug-free. In the TaskFlow lure, server.js imports a trojanized package, colorized_terminal 2.1.0 or pretty-log 2.1.0, bundled inside node_modules (not published on npm). The package launches an implant from node_modules/.cache/<hex>/index.js as a detached process. Variants were found in Afghanistan (first sample, a software engineer), Egypt and Ethiopia.
NodeRabbit is a cross-platform (Windows, Linux, macOS) Node.js RAT. C2 requests are JSON encrypted with AES-256-GCM (key = SHA-256 of an embedded seed) and sent to Azure App Service hosts with failover. Variant 1 has 11 commands (sys:info, proc:list, fs:read/write/delete, script:exec and others) and persists as a fake Microsoft Edge update. Variant 2 adds anti-analysis checks (low RAM/CPU, short uptime, analyst usernames or tools), corporate proxy support (including NTLM/Negotiate via curl.exe) and masquerades as 'Intel Driver & Support Assistant'. Variant 3 uses /sdk/v2/* endpoints, adds 12 commands including Outlook OST/PST address harvesting, a fake VS Code extension ('GitHub Copilot Helper'), Git-hook injection (post-merge/post-checkout marked '# shepherd-persist') and WSL-based persistence.
PollCat is a second, obfuscated JavaScript RAT delivered in a React lure (RankChallenge-react, run via 'npm i && node index.js') that asks for a recruiter-supplied six-digit OTP validated against lifespotify.com. The implant registers with C2 before OTP entry, so a failed OTP does not stop it. It polls every 2 minutes with up to 5 s jitter, declares 22 commands (RUN, RUN_HIDDEN, EVAL_JS, UPLOAD, DOWNLOAD, ZIP, RUNDLL and others; WS_DOWNLOAD, REQUEST_ELEVATION and PERSIST are unimplemented) and enumerates 24 security/software-vendor folders. Kaspersky links both to Mirage Kitten's Retrograde/MiniFast backdoor through the shared HTTP 400 socketId handshake, identical timing defaults, shared command IDs, victimology and Azure/Cloudflare infrastructure.
Note: DarkOwl describes NodeRabbit as targeting Linux and macOS; Kaspersky documents Windows, Linux and macOS variants. Kaspersky also suggests the lure projects may be AI-assisted or template-generated. Browser-credential theft is not described in the Securelist-derived sources.
MITRE ATT&CK techniques used in TL-2026-3061
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1497.001 System Checks
Persistence
T1053.003 Cron; T1053.005 Scheduled Task; T1543.001 Launch Agent; T1546 Event Triggered Execution; T1547.001 Registry Run Keys / Startup Folder
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
Execution
T1059.007 JavaScript; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1573.001 Symmetric Cryptography
Collection
T1114.001 Local Email Collection
Initial Access
T1566.003 Spearphishing via Service
Resource Development
Affected products and versions in Malware-as-a-Service (MaaS) Ecosystem Overview, Including
- Node.js / npm ecosystem — Developer workstations running untrusted Node.js projects (Windows, Linux, macOS)
Vulnerable versions: colorized_terminal 2.1.0 (trojanized, bundled in lure archives); pretty-log 2.1.0 (trojanized, bundled in lure archives)
Remediation for Malware-as-a-Service (MaaS) Ecosystem Overview, Including
Immediate actions
- Block the listed Azure App Service, custom C2 and OTP domains at DNS/proxy and alert on historical hits
- Hunt endpoints for node_modules/.cache/<hex>/index.js, colorized_terminal 2.1.0 and pretty-log 2.1.0, and for the listed persistence artifacts (IntelDriverSupportUpdate task, MicrosoftEdgeUpdate Run value, com.microsoft.edgeupdate / com.intel.dsa.helper LaunchAgents, '# shepherd-persist' in .git/hooks)
- Rotate cloud credentials, tokens and secrets on any machine that ran an unsolicited coding challenge
Workarounds
- Inspect server.js and startup files before running any received project; review dependencies bundled in node_modules
- Remove unexpected VS Code extensions and re-enable Workspace Trust
Longer-term hardening
- Run third-party coding assessments only in isolated VMs/containers without production credentials or source access
- Deploy EDR with behavioral detection for detached Node.js children, Node.js persistence creation and Git-hook modification
- Train developers to verify recruiters through the employer's official channel
- Restrict network egress to *.azurewebsites.net from developer workstations where feasible
Timeline of Malware-as-a-Service (MaaS) Ecosystem Overview, Including
- Start of the window (15 May to 3 Jul 2026) in which Mirage Kitten registered the campaign domains; lifespotify.com was registered in late June 2026
- End of the domain-registration window observed by Kaspersky for the NodeRabbit/PollCat infrastructure
- The Hacker News and Cyber Security News/Cryptika report the fake-recruiter coding-test campaign targeting developers
- Kaspersky attributes the malware to Mirage Kitten (Nimbus Manticore) with high confidence via shared handshake, command IDs, timing defaults and infrastructure overlap with Retrograde/MiniFast
- Kaspersky (Omar Amin) publishes 'Mirage Kitten: new backdoors NodeRabbit and PollCat' on Securelist, documenting three NodeRabbit variants (Afghanistan, Egypt, Ethiopia) and PollCat
- DarkOwl publishes 'What is Malware as a Service?', using Nimbus Manticore's NodeRabbit/PollCat campaign as a case study
Sources cited for Malware-as-a-Service (MaaS) Ecosystem Overview, Including
- What is Malware as a Service? (DarkOwl)
- Mirage Kitten: new backdoors NodeRabbit and PollCat (Securelist, Kaspersky)
- Iranian Hackers Pose as Recruiters to Deploy Cross-Platform RATs (The Hacker News)
- Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers (Cryptika)
- Nimbus Manticore recruitment brief (CraftedSignal)
- Iranian Cybercriminals Disguise Themselves as Recruiters to Distribute Cross-Platform RATs via Coding Assessments (RSWebSols)
- Iranian hackers cross-platform RATs (SecNews)
- Gefälschtes Vorstellungsgespräch (IT-Daily)
Detection coverage for TL-2026-3061
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3061 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.