Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI assistants, reducing the chance the malicious code would be flagged during review.
Key findings
- Attackers used a “recruiter persona on LinkedIn” to contact software engineers and deliver trojanized take-home coding tests.
- The coding-test README set a short deadline and banned AI assistants, apparently to prevent AI code review from spotting the malicious dependency/import.
- Malware was delivered as two new families (NodeRabbit and PollCat) hidden inside developer projects that victims would run during the assessment.
- PollCat was disguised as a React challenge that asked for a “six-digit access code” to add urgency, but the malware began communicating as soon as the app loaded.
- Victims were observed in fintech and aviation organizations across Egypt, Ethiopia, and Afghanistan.
Who’s being targeted
- Commonly targeted roles: Engineering, Software Development, Recruiting/HR, IT Security, Hiring Managers.
- Affected industries: Fintech, Aviation.
- Attack channels: linkedin, website.
- Impersonated: External recruiter (job opportunity), Recruiter / hiring assessment platform.
Awareness takeaways
- Treat unsolicited LinkedIn job outreach (especially with take-home code tests) as a security risk and verify the recruiter and employer through trusted channels before downloading anything.
- Be suspicious of ‘anti-cheating’ instructions that block normal safety steps (e.g., “no AI assistants” / no code review) in coding assessments.
- Do not run unknown assessment projects on your main work machine; use a controlled, isolated environment for any third-party code you must execute.
- Watch for ‘legitimate-looking’ cloud-hosted download links (e.g., S3) used to make malicious content seem trustworthy.
Red flags to watch for
- Unsolicited recruiter outreach with pressure to complete a test quickly (e.g., a 3-hour limit)
- Instructions that discourage normal safety checks (e.g., banning AI assistants/code review)
- Coding test delivered as an archive/project with unusual or unknown dependencies/packages
- Requirement to run an untrusted project locally to view the ‘test’
- A countdown timer or urgency pressure that discourages careful review
- The app begins network communications immediately when launched
Read the video transcript
You get a LinkedIn message from a recruiter, big-name role, and a take‑home coding test on a legit‑looking Amazon S3 link. But this isn’t just a test. Mirage Kitten used fake recruiters to send trojanized projects, NodeRabbit and PollCat, malware that runs the moment you start the app. Their README looked real: three-hour deadline, React bug‑fix task, even a six‑digit access code. It also banned AI assistants, so you’d rush and never let anything scan the code. Here’s your move: if a recruiter sends a coding test, never run it on your main work machine, open it only in an isolated environment or don’t run it at all.