Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Securelist · High sophistication
Last updated July 30, 2026

Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected people to malicious archives on file‑sharing services, leading to new malware deployments.

How the attack worked

Researchers observed Mirage Kitten running highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa. Two lure types stood out. The first used recruitment-themed content impersonating trusted brands and hiring platforms, drawing targets toward a hiring portal that led to a screening or job-description archive. The second used lookalike videoconferencing pages that appeared to offer a normal meeting join flow but instead redirected victims to malicious archives hosted on third-party file-sharing services. Both paths ended in new malware deployments once the archive was opened.

Why it succeeded

The campaign relied on highly tailored social engineering lures against selected targets rather than mass, generic messaging. Recruitment pretexts feel routine for HR staff and hiring managers, so an unexpected screening pack does not automatically read as suspicious. Meeting invites carry similar authority, since employees are conditioned to click links to join calls quickly. Hosting final payloads on third-party file-sharing services also let the attackers avoid relying on infrastructure that looked obviously malicious at first glance, making the download step blend in with legitimate business file transfers.

What to watch for

  • Unsolicited recruiting messages that pressure a recipient to open an archive or download a screening pack
  • Sender or brand names that look legitimate but link to non-standard domains or third-party file-sharing sites
  • Meeting links that don't behave like normal video calls, especially ones that redirect to a file download instead of a live session
  • Messages that feel unusually specific to your role, which can indicate targeted reconnaissance rather than trustworthiness

Building resistance

Organizations in aerospace, defense, telecom, government, and financial services, the sectors named in this activity, should treat recruitment and meeting-related file downloads as a distinct risk category. Practical steps include verifying unexpected recruiting outreach through known, trusted contact channels before opening any attachment, and training staff to recognize that a meeting link redirecting to a file download is not standard behavior for common videoconferencing tools. Because these lures relied on highly tailored details, awareness programs should emphasize that personalization is not proof of legitimacy. Reinforcing consistent verification habits, regardless of how convincing or specific a message appears, reduces the chance that a single well-crafted lure leads to malware execution across an organization.

Key findings

  • The activity included “highly targeted spear-phishing campaigns” with “highly tailored social engineering lures against selected targets.”
  • Lures included “recruitment-themed content impersonating trusted brands and hiring platforms” and “lookalike videoconferencing pages that redirected victims to malicious archives hosted on third-party file-sharing services.”
  • Victims were observed in multiple countries including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, spanning government, aviation, telecom, and financial-sector entities.
  • Observed infrastructure included domains such as realhealthshop[.]com, tjconsultingservices[.]com, and smartconnect[.]azurewebsites[.]net, used for command-and-control and tunneling.

Who’s being targeted

  • Commonly targeted roles: HR/Recruiting, Executives, Aerospace/Aviation staff, Defense program teams, Telecom employees, General workforce (phishing awareness).
  • Affected industries: Aerospace and aviation, Defense, Telecommunications, Government, Financial services.
  • Attack channels: email, website.
  • Impersonated: Trusted brand or hiring platform (recruitment brand impersonation), Video conferencing service (lookalike meeting page).

Red flags to watch for

  • Unexpected recruiting message that pressures you to open an archive or download files
  • Sender/brand looks legitimate but the link goes to a non-standard domain or third-party file-sharing site
  • Overly tailored message aimed at a specific person/role
  • Meeting link leads to a lookalike site (slightly misspelled/odd domain)
  • The “meeting” flow unexpectedly redirects to downloading an archive
  • File download is hosted on a third-party file-sharing service rather than the normal meeting platform
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Mirage Kitten and who did it target?

Mirage Kitten is an espionage-focused threat group that ran highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa.

How did the fake hiring lures work?

Attackers sent recruitment-themed messages impersonating trusted brands and hiring platforms, directing targets to portals that led to malicious archive downloads hosted on third-party file-sharing services.

What role did fake videoconferencing pages play?

Lookalike videoconferencing pages redirected victims away from a normal meeting flow toward malicious archives hosted on third-party file-sharing services, ultimately deploying malware.

Why were these lures effective despite being highly targeted?

The lures were highly tailored to specific individuals and roles, which made them appear more credible even though personalization does not indicate legitimacy.

Read the video transcript

You get an email: “Interview screening materials for your application.” Looks legit, big-name brand logo, tailored right to your role. Behind the scenes, this is Mirage Kitten: highly targeted spear‑phishing using fake recruitment portals and lookalike meeting pages that push malware archives from file‑sharing sites. Here’s the trap: the email says hiring portal, but the link quietly sends you to an odd domain or a fake video‑conferencing page, which then redirects again to a .zip on a random file‑sharing site. Your move: if a recruiting email or meeting link wants you to download a .zip, stop, don’t open it, forward it to security and confirm the request through a known, trusted contact.

Similar attacks

Fake LinkedIn Tests and Job Interviews Push Malware

Fake LinkedIn Tests and Job Interviews Push Malware

This weekly threat bulletin includes real-world campaigns where attackers impersonate recruiters and use fake hiring steps to trick people into running malicious files. One campaign uses fake LinkedIn coding tests delivered via cloud links, and another uses fake job interviews with trojanized macOS…

September 7, 2026
Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Fake LinkedIn Coding Tests Deliver Mirage Kitten Malware

Kaspersky reported that Iran-linked APT Mirage Kitten approached software engineers on LinkedIn using fake recruiter personas and sent “coding challenges” that were actually trojanized projects. The lure used legitimate-looking cloud hosting (Amazon S3) and even instructed victims not to use AI…

September 2, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Fake Freelancer Accounts Pushed Malicious Excel Macros

Fake Freelancer Accounts Pushed Malicious Excel Macros

U.S. prosecutors say a Russian national used hundreds of fake accounts on a freelance platform to send Excel files that tricked users into enabling macros, which then downloaded remote-control malware. The campaign targeted tens of thousands of users and led to thousands of infections, enabling…

September 2, 2026