Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Security Affairs · High sophistication
Last updated September 2, 2026

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI assistants, reducing the chance the malicious code would be flagged during review.

Key findings

  • Attackers used a “recruiter persona on LinkedIn” to contact software engineers and deliver trojanized take-home coding tests.
  • The coding-test README set a short deadline and banned AI assistants, apparently to prevent AI code review from spotting the malicious dependency/import.
  • Malware was delivered as two new families (NodeRabbit and PollCat) hidden inside developer projects that victims would run during the assessment.
  • PollCat was disguised as a React challenge that asked for a “six-digit access code” to add urgency, but the malware began communicating as soon as the app loaded.
  • Victims were observed in fintech and aviation organizations across Egypt, Ethiopia, and Afghanistan.

Who’s being targeted

  • Commonly targeted roles: Engineering, Software Development, Recruiting/HR, IT Security, Hiring Managers.
  • Affected industries: Fintech, Aviation.
  • Attack channels: linkedin, website.
  • Impersonated: External recruiter (job opportunity), Recruiter / hiring assessment platform.

Awareness takeaways

  • Treat unsolicited LinkedIn job outreach (especially with take-home code tests) as a security risk and verify the recruiter and employer through trusted channels before downloading anything.
  • Be suspicious of ‘anti-cheating’ instructions that block normal safety steps (e.g., “no AI assistants” / no code review) in coding assessments.
  • Do not run unknown assessment projects on your main work machine; use a controlled, isolated environment for any third-party code you must execute.
  • Watch for ‘legitimate-looking’ cloud-hosted download links (e.g., S3) used to make malicious content seem trustworthy.

Red flags to watch for

  • Unsolicited recruiter outreach with pressure to complete a test quickly (e.g., a 3-hour limit)
  • Instructions that discourage normal safety checks (e.g., banning AI assistants/code review)
  • Coding test delivered as an archive/project with unusual or unknown dependencies/packages
  • Requirement to run an untrusted project locally to view the ‘test’
  • A countdown timer or urgency pressure that discourages careful review
  • The app begins network communications immediately when launched
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get a LinkedIn message from a recruiter, big-name role, and a take‑home coding test on a legit‑looking Amazon S3 link. But this isn’t just a test. Mirage Kitten used fake recruiters to send trojanized projects, NodeRabbit and PollCat, malware that runs the moment you start the app. Their README looked real: three-hour deadline, React bug‑fix task, even a six‑digit access code. It also banned AI assistants, so you’d rush and never let anything scan the code. Here’s your move: if a recruiter sends a coding test, never run it on your main work machine, open it only in an isolated environment or don’t run it at all.

Similar attacks

Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Recruiters Lure Devs Into Malware “Coding Tests”

Fake Recruiters Lure Devs Into Malware “Coding Tests”

An Iran-linked espionage group contacted developers and other tech specialists with fake job offers on LinkedIn and similar platforms. Victims were pushed to quickly download and run “coding challenges” that secretly installed new malware, giving attackers remote access and long-term persistence.…

September 1, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026