This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send convincing emails and route victims to fake Microsoft 365 login pages, including adversary-in-the-middle kits designed to bypass MFA.
Key findings
- Iran-linked actors (Mirage Kitten / UNC1549) used fake recruiter outreach on LinkedIn and job platforms to lure developers into downloading and running trojanized “coding test” archives.
- Some “coding tests” used time pressure and single-use codes, and even banned AI coding assistants to reduce the chance victims would notice malicious code.
- A separate phishing campaign routed lures through trusted cloud services (Google Cloud, AWS S3, Azure, Firebase, Cloudflare) to look legitimate and pass email authentication checks.
- Victims were funneled through CAPTCHA gates to fake Microsoft 365 login pages; adversary-in-the-middle tooling can capture session tokens to bypass MFA.
Who’s being targeted
- Commonly targeted roles: Developers, Engineering leadership, Finance and Accounting, IT / Identity and Access Management (IAM), Security awareness program participants.
- Affected industries: Finance, Aviation, Aerospace, Fintech, Software development.
- Attack channels: linkedin, email, website.
- Impersonated: Recruiter / hiring team for an aviation, aerospace, or fintech employer, Google Cloud / Microsoft 365 sign-in workflow.
Awareness takeaways
- Treat unsolicited recruiter messages and “coding tests” as high risk, verify the recruiter and do not run unknown projects on your work device.
- Be suspicious of urgent hiring steps that try to reduce scrutiny (time pressure, single-use codes, or bans on tools that could help you review code).
- Don’t trust an email just because it comes from a well-known cloud domain; attackers can abuse legitimate cloud email features to send convincing lures.
- MFA isn’t a guarantee if you’re tricked into logging into a fake page, adversary-in-the-middle phishing can steal session tokens.
Red flags to watch for
- Unsolicited recruiter approach pushing you to run a project locally
- Time pressure and “single-use access codes” to rush execution
- Instructions that ban AI coding assistants (attempting to reduce scrutiny)
- Unexpected CAPTCHA gate before a corporate login
- Login page hosted on cloud storage (e.g., AWS S3) instead of your organization’s normal sign-in domain
- Email appears to come from a trusted cloud domain but is unrelated to an expected business process
Read the video transcript
A LinkedIn recruiter sends you a "coding test" zip and a Google email asks you to log into Microsoft 365. Both can be traps. Iran-linked Mirage Kitten has posed as aviation and fintech recruiters on LinkedIn, pushing devs to run trojanized "coding tests" that drop NodeRabbit and PollCat malware on Windows, macOS, and Linux. At the same time, phishers abuse Google Cloud and AWS so emails pass SPF, DKIM, DMARC, then funnel you through a random CAPTCHA to a fake Microsoft 365 page that can even steal MFA session tokens. Aha moment: if a stranger recruiter wants you to run code, or a cloud email sends you through a CAPTCHA to log in, stop and verify out-of-band before you open the file or type your password.