Fake LinkedIn Tests and Job Interviews Push Malware

Check Point Research · Medium sophistication
Last updated September 8, 2026

This weekly threat bulletin includes real-world campaigns where attackers impersonate recruiters and use fake hiring steps to trick people into running malicious files. One campaign uses fake LinkedIn coding tests delivered via cloud links, and another uses fake job interviews with trojanized macOS installers that impersonate legitimate apps.

How the attack worked

This threat bulletin describes two related recruiting-themed campaigns. In the first, activity linked to Mirage Kitten uses fake LinkedIn coding tests distributed through cloud links. Opening the test triggers installation of cross-platform implants, including malware referred to as NodeRabbit and PollCat. In the second, Contagious Interview activity relies on fake job interviews that ask candidates to download trojanized macOS disk images or installer packages disguised as legitimate Mac applications. Both approaches use the hiring process itself as the delivery mechanism, since a coding test or software install request feels like a normal part of applying for a technical job.

Why it succeeded

These lures work because they exploit a process most developers and engineers go through routinely: technical assessments and interview setup steps. A recruiting message that includes a cloud link to a coding test, or an interview step that asks for a local install, does not look unusual on its face. The pretext also targets people who are motivated to move quickly through a hiring process and may be less likely to question extra steps like installing an app or opening a file from an unfamiliar link.

What to watch for

  • Unsolicited recruiting outreach that pushes you toward a cloud-hosted link rather than a known applicant tracking system
  • A “coding test” that requires downloading or running something locally instead of working in a browser-based environment
  • Interview processes that ask you to install a macOS disk image or installer package from outside official vendor channels
  • Hiring steps that bypass normal HR or recruiting communication channels
  • Unexpected security prompts or unusual install steps presented as part of a technical assessment

How to build resistance

Organizations, especially in fintech and aviation where these campaigns have reportedly targeted staff, should treat unsolicited recruiting messages and coding tests as a high-risk channel. Employees should verify a recruiter and the hiring process before opening links or downloading files, and should never install software as part of an interview or assessment unless it comes from a trusted, official source and is approved by IT or security. Because developers, engineers, and other high-demand technical roles are the most likely targets, awareness training should specifically address recruiting-themed lures and reinforce that legitimate hiring processes rarely require installing unverified software on a personal or work device.

Key findings

  • Iran-linked Mirage Kitten used fake LinkedIn coding tests delivered through cloud links to install cross-platform implants.
  • North Korea-linked Contagious Interview activity used fake job interviews and trojanized macOS disk images/installer packages impersonating legitimate Mac apps.
  • Targets called out include fintech and aviation organizations in Egypt, Ethiopia, and Afghanistan.

Who’s being targeted

  • Commonly targeted roles: Developers, Engineering, IT, HR/Recruiting, Fintech staff, Aviation staff, Employees using macOS.
  • Affected industries: Financial technology (fintech), Aviation, Government, Education.
  • Attack channels: linkedin, website.
  • Impersonated: Recruiter / hiring team (via LinkedIn), Legitimate Mac application vendor (impersonated) / recruiter.

Red flags to watch for

  • Unsolicited recruiting outreach pushing you to open a cloud-hosted link
  • “Coding test” content that requires running or installing something locally
  • Hiring steps that bypass normal HR/recruiting channels
  • Interview process requires installing software from an unverified source
  • Installer package not obtained from official vendor channels (e.g., App Store or vendor website)
  • Unexpected security prompts or unusual install steps during a “test”
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake LinkedIn coding test attack work?

Attackers linked to Mirage Kitten send fake LinkedIn coding tests distributed through cloud links that install cross-platform implants such as NodeRabbit and PollCat when opened.

What is the fake job interview macOS attack?

Contagious Interview activity uses fake job interviews to convince candidates to download trojanized macOS disk images or installer packages that impersonate legitimate Mac applications.

Who is being targeted by these campaigns?

The campaigns target developers, engineers, and IT staff, with reported targets including fintech and aviation organizations in Egypt, Ethiopia, and Afghanistan.

What red flags should job seekers watch for?

Warning signs include unsolicited recruiting outreach pushing a cloud link, coding tests that require installing something locally, and interview steps that ask you to install software from an unverified source.

Read the video transcript

Imagine this: a LinkedIn recruiter sends you a coding test for your dream fintech role. Iran-linked Mirage Kitten has used fake LinkedIn coding tests, sent as cloud links, to install NodeRabbit and PollCat malware on candidates’ machines. North Korea’s Contagious Interview even turns fake job interviews into malware installs, pushing trojanized macOS DMG or PKG files that pretend to be legit Mac apps. Here’s the move: if any recruiter asks you to install software or run a downloaded test, stop and send it to IT or security first. No approval, no install.

Similar attacks

Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected…

July 28, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026