Kaspersky GReAT has spotted a new campaign by the Mirage Kitten group. Attackers pose as recruiters from big tech firms on LinkedIn. They contact software engineers in aviation and fintech, mainly in Egypt, Ethiopia and Afghanistan. Related malware has also shown up in Germany, Turkey, Israel, India and Ireland. Targets get invited to a technical test and receive a link to download a coding challenge from Amazon cloud storage. The message sets a tight one-to-three-hour deadline and warns against using AI coding tools that might catch the hidden malicious code. Once the developer runs the challenge, the malware installs quietly in the background. The group has moved from older C, C++ or Go malware that only hit Windows to Node.js and JavaScript tools that work on Windows, macOS and Linux. Kaspersky calls this a clear change in Mirage Kitten tactics.
Kaspersky GReAT has spotted a new campaign by the Mirage Kitten group. Attackers pose as recruiters from big tech firms on LinkedIn. They contact software engineers in aviation and fintech, mainly in Egypt, Ethiopia and Afghanistan. Related malware has also shown up in Germany, Turkey, Israel, India and Ireland. Targets get invited to a technical test and receive a link to download a coding challenge from Amazon cloud storage. The message sets a tight one-to-three-hour deadline and warns against using AI coding tools that might catch the hidden malicious code. Once the developer runs the challenge, the malware installs quietly in the background. The group has moved from older C, C++ or Go malware that only hit Windows to Node.js and JavaScript tools that work on Windows, macOS and Linux. Kaspersky calls this a clear change in Mirage Kitten tactics.