# Malware-as-a-Service (MaaS) Ecosystem Overview, Including Nimbus Manticore (Mirage Kitten) NodeRabbit and PollCat Fake-Recruitment Campaign

> DarkOwl's MaaS primer cites the Iranian group Nimbus Manticore (Mirage Kitten, 'Iranian Dream Job'), which uses fake-recruiter coding challenges to deliver two previously undocumented Node.js RATs, NodeRabbit and PollCat. Kaspersky's Securelist research attributes the activity with high confidence and confirmed victims in aviation/aerospace and fintech in Afghanistan, Egypt and Ethiopia.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3061
- **ID:** TL-2026-3061
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC1549 (Iran)
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DarkOwl (2026-10-08) explains the Malware-as-a-Service model in which developers build, market and lease malware and supporting infrastructure (infostealers, RATs, botnet malware, ransomware) to other actors. The six stages it describes are development, distribution/marketing, purchase/subscription, deployment, collection/monetization, and resale/further exploitation. The article is largely educational and lists no IOCs; its case study is Nimbus Manticore, a state-linked actor rather than a pure MaaS vendor.

The underlying research is Kaspersky's Securelist report 'Mirage Kitten: new backdoors NodeRabbit and PollCat' (2026-09-01, Omar Amin). A fake talent-acquisition persona contacts developers on LinkedIn and other job platforms and sends a link to a time-limited coding assessment hosted in an Amazon S3 bucket (oracle-challenge, us-east-1). The README imposes a three-hour limit, bans AI assistants, and claims the server component is already bug-free. In the TaskFlow lure, server.js imports a trojanized package, colorized_terminal 2.1.0 or pretty-log 2.1.0, bundled inside node_modules (not published on npm). The package launches an implant from node_modules/.cache/<hex>/index.js as a detached process. Variants were found in Afghanistan (first sample, a software engineer), Egypt and Ethiopia.

NodeRabbit is a cross-platform (Windows, Linux, macOS) Node.js RAT. C2 requests are JSON encrypted with AES-256-GCM (key = SHA-256 of an embedded seed) and sent to Azure App Service hosts with failover. Variant 1 has 11 commands (sys:info, proc:list, fs:read/write/delete, script:exec and others) and persists as a fake Microsoft Edge update. Variant 2 adds anti-analysis checks (low RAM/CPU, short uptime, analyst usernames or tools), corporate proxy support (including NTLM/Negotiate via curl.exe) and masquerades as 'Intel Driver & Support Assistant'. Variant 3 uses /sdk/v2/* endpoints, adds 12 commands including Outlook OST/PST address harvesting, a fake VS Code extension ('GitHub Copilot Helper'), Git-hook injection (post-merge/post-checkout marked '# shepherd-persist') and WSL-based persistence.

PollCat is a second, obfuscated JavaScript RAT delivered in a React lure (RankChallenge-react, run via 'npm i && node index.js') that asks for a recruiter-supplied six-digit OTP validated against lifespotify.com. The implant registers with C2 before OTP entry, so a failed OTP does not stop it. It polls every 2 minutes with up to 5 s jitter, declares 22 commands (RUN, RUN_HIDDEN, EVAL_JS, UPLOAD, DOWNLOAD, ZIP, RUNDLL and others; WS_DOWNLOAD, REQUEST_ELEVATION and PERSIST are unimplemented) and enumerates 24 security/software-vendor folders. Kaspersky links both to Mirage Kitten's Retrograde/MiniFast backdoor through the shared HTTP 400 socketId handshake, identical timing defaults, shared command IDs, victimology and Azure/Cloudflare infrastructure.

Note: DarkOwl describes NodeRabbit as targeting Linux and macOS; Kaspersky documents Windows, Linux and macOS variants. Kaspersky also suggests the lure projects may be AI-assisted or template-generated. Browser-credential theft is not described in the Securelist-derived sources.

## MITRE ATT&CK

- T1585.001 Social Media Accounts
- T1583.006 Web Services
- T1566.003 Spearphishing via Service
- T1204.002 Malicious File
- T1059.007 JavaScript
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1053.003 Cron
- T1543.001 Launch Agent
- T1546 Event Triggered Execution
- T1036.005 Match Legitimate Resource Name or Location
- T1497.001 System Checks
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518.001 Security Software Discovery
- T1114.001 Local Email Collection
- T1071.001 Web Protocols
- T1573.001 Symmetric Cryptography

## Sources

- [What is Malware as a Service? (DarkOwl)](https://www.darkowl.com/blog-content/what-is-malware-as-a-service/)
- [Mirage Kitten: new backdoors NodeRabbit and PollCat (Securelist, Kaspersky)](https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/)
- [Iranian Hackers Pose as Recruiters to Deploy Cross-Platform RATs (The Hacker News)](https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html)
- [Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers (Cryptika)](https://www.cryptika.com/hackers-pose-as-recruiters-and-send-fake-coding-tests-to-infect-software-developers/)
- [Nimbus Manticore recruitment brief (CraftedSignal)](https://feed.craftedsignal.io/briefs/2026-09-nimbus-manticore-recruitment/)
- [Iranian Cybercriminals Disguise Themselves as Recruiters to Distribute Cross-Platform RATs via Coding Assessments (RSWebSols)](https://www.rswebsols.com/news/iranian-cybercriminals-disguise-themselves-as-recruiters-to-distribute-cross-platform-rats-via-coding-assessments/)
- [Iranian hackers cross-platform RATs (SecNews)](https://www.secnews.gr/en/729715/iranian-hackers-cross-platform-rats/)
- [Gefälschtes Vorstellungsgespräch (IT-Daily)](https://www.it-daily.net/it-sicherheit/cybercrime/hacker-programmiertests)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3061
