Kaspersky said Mirage Kitten is targeting aviation, aerospace, and fintech developers with fake recruiting tests that deliver two previously undocumented cross-platform remote-access trojans, NodeRabbit and PollCat. The campaign has shown up in Afghanistan, Egypt, and Ethiopia, and it uses job-platform lures and recruiter messages to get victims to open the files themselves.
The trap is a coding challenge that looks like a normal hiring exercise but carries hidden code that runs when the candidate opens or executes it. Once it does, NodeRabbit can gather information, change files, and run more commands on Windows, Linux, or macOS, while PollCat is built to keep access and drop additional files. In practice, the attacker gets the developer to launch the payload on a trusted work machine.
That matters because a developer workstation can hold source code, build tools, internal documentation, and cached secrets. For organizations that recruit through LinkedIn or other job platforms, the exposure sits in the hiring workflow itself: the machine compromised here can become a path into repositories and internal systems, even if the inbox never looked obviously malicious.