Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Securelist · High sophistication
Last updated July 30, 2026

Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected people to malicious archives on file‑sharing services, leading to new malware deployments.

How the attack worked

Researchers observed Mirage Kitten running highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa. Two lure types stood out. The first used recruitment-themed content impersonating trusted brands and hiring platforms, drawing targets toward a hiring portal that led to a screening or job-description archive. The second used lookalike videoconferencing pages that appeared to offer a normal meeting join flow but instead redirected victims to malicious archives hosted on third-party file-sharing services. Both paths ended in new malware deployments once the archive was opened.

Why it succeeded

The campaign relied on highly tailored social engineering lures against selected targets rather than mass, generic messaging. Recruitment pretexts feel routine for HR staff and hiring managers, so an unexpected screening pack does not automatically read as suspicious. Meeting invites carry similar authority, since employees are conditioned to click links to join calls quickly. Hosting final payloads on third-party file-sharing services also let the attackers avoid relying on infrastructure that looked obviously malicious at first glance, making the download step blend in with legitimate business file transfers.

What to watch for

  • Unsolicited recruiting messages that pressure a recipient to open an archive or download a screening pack
  • Sender or brand names that look legitimate but link to non-standard domains or third-party file-sharing sites
  • Meeting links that don't behave like normal video calls, especially ones that redirect to a file download instead of a live session
  • Messages that feel unusually specific to your role, which can indicate targeted reconnaissance rather than trustworthiness

Building resistance

Organizations in aerospace, defense, telecom, government, and financial services, the sectors named in this activity, should treat recruitment and meeting-related file downloads as a distinct risk category. Practical steps include verifying unexpected recruiting outreach through known, trusted contact channels before opening any attachment, and training staff to recognize that a meeting link redirecting to a file download is not standard behavior for common videoconferencing tools. Because these lures relied on highly tailored details, awareness programs should emphasize that personalization is not proof of legitimacy. Reinforcing consistent verification habits, regardless of how convincing or specific a message appears, reduces the chance that a single well-crafted lure leads to malware execution across an organization.

Key findings

  • The activity included “highly targeted spear-phishing campaigns” with “highly tailored social engineering lures against selected targets.”
  • Lures included “recruitment-themed content impersonating trusted brands and hiring platforms” and “lookalike videoconferencing pages that redirected victims to malicious archives hosted on third-party file-sharing services.”
  • Victims were observed in multiple countries including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, spanning government, aviation, telecom, and financial-sector entities.
  • Observed infrastructure included domains such as realhealthshop[.]com, tjconsultingservices[.]com, and smartconnect[.]azurewebsites[.]net, used for command-and-control and tunneling.

Who’s being targeted

  • Commonly targeted roles: HR/Recruiting, Executives, Aerospace/Aviation staff, Defense program teams, Telecom employees, General workforce (phishing awareness).
  • Affected industries: Aerospace and aviation, Defense, Telecommunications, Government, Financial services.
  • Attack channels: email, website.
  • Impersonated: Trusted brand or hiring platform (recruitment brand impersonation), Video conferencing service (lookalike meeting page).

Red flags to watch for

  • Unexpected recruiting message that pressures you to open an archive or download files
  • Sender/brand looks legitimate but the link goes to a non-standard domain or third-party file-sharing site
  • Overly tailored message aimed at a specific person/role
  • Meeting link leads to a lookalike site (slightly misspelled/odd domain)
  • The “meeting” flow unexpectedly redirects to downloading an archive
  • File download is hosted on a third-party file-sharing service rather than the normal meeting platform
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Mirage Kitten and who did it target?

Mirage Kitten is an espionage-focused threat group that ran highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa.

How did the fake hiring lures work?

Attackers sent recruitment-themed messages impersonating trusted brands and hiring platforms, directing targets to portals that led to malicious archive downloads hosted on third-party file-sharing services.

What role did fake videoconferencing pages play?

Lookalike videoconferencing pages redirected victims away from a normal meeting flow toward malicious archives hosted on third-party file-sharing services, ultimately deploying malware.

Why were these lures effective despite being highly targeted?

The lures were highly tailored to specific individuals and roles, which made them appear more credible even though personalization does not indicate legitimacy.

Read the video transcript

You get an email: “Interview screening materials for your application.” Looks legit, big-name brand logo, tailored right to your role. Behind the scenes, this is Mirage Kitten: highly targeted spear‑phishing using fake recruitment portals and lookalike meeting pages that push malware archives from file‑sharing sites. Here’s the trap: the email says hiring portal, but the link quietly sends you to an odd domain or a fake video‑conferencing page, which then redirects again to a .zip on a random file‑sharing site. Your move: if a recruiting email or meeting link wants you to download a .zip, stop, don’t open it, forward it to security and confirm the request through a known, trusted contact.

Similar attacks

OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026
Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure…

July 17, 2026