Mirage Kitten Uses Fake Hiring Lures to Drop Malware

Securelist · High sophistication
Last updated July 30, 2026

Researchers report Mirage Kitten (an espionage-focused threat group) targeted organizations in the Middle East and Africa using highly tailored spear‑phishing. The lures included recruitment-themed messages impersonating trusted brands/hiring sites and fake videoconferencing pages that redirected people to malicious archives on file‑sharing services, leading to new malware deployments.

How the attack worked

Researchers observed Mirage Kitten running highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa. Two lure types stood out. The first used recruitment-themed content impersonating trusted brands and hiring platforms, drawing targets toward a hiring portal that led to a screening or job-description archive. The second used lookalike videoconferencing pages that appeared to offer a normal meeting join flow but instead redirected victims to malicious archives hosted on third-party file-sharing services. Both paths ended in new malware deployments once the archive was opened.

Why it succeeded

The campaign relied on highly tailored social engineering lures against selected targets rather than mass, generic messaging. Recruitment pretexts feel routine for HR staff and hiring managers, so an unexpected screening pack does not automatically read as suspicious. Meeting invites carry similar authority, since employees are conditioned to click links to join calls quickly. Hosting final payloads on third-party file-sharing services also let the attackers avoid relying on infrastructure that looked obviously malicious at first glance, making the download step blend in with legitimate business file transfers.

What to watch for

  • Unsolicited recruiting messages that pressure a recipient to open an archive or download a screening pack
  • Sender or brand names that look legitimate but link to non-standard domains or third-party file-sharing sites
  • Meeting links that don't behave like normal video calls, especially ones that redirect to a file download instead of a live session
  • Messages that feel unusually specific to your role, which can indicate targeted reconnaissance rather than trustworthiness

Building resistance

Organizations in aerospace, defense, telecom, government, and financial services, the sectors named in this activity, should treat recruitment and meeting-related file downloads as a distinct risk category. Practical steps include verifying unexpected recruiting outreach through known, trusted contact channels before opening any attachment, and training staff to recognize that a meeting link redirecting to a file download is not standard behavior for common videoconferencing tools. Because these lures relied on highly tailored details, awareness programs should emphasize that personalization is not proof of legitimacy. Reinforcing consistent verification habits, regardless of how convincing or specific a message appears, reduces the chance that a single well-crafted lure leads to malware execution across an organization.

Key findings

  • The activity included “highly targeted spear-phishing campaigns” with “highly tailored social engineering lures against selected targets.”
  • Lures included “recruitment-themed content impersonating trusted brands and hiring platforms” and “lookalike videoconferencing pages that redirected victims to malicious archives hosted on third-party file-sharing services.”
  • Victims were observed in multiple countries including Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, spanning government, aviation, telecom, and financial-sector entities.
  • Observed infrastructure included domains such as realhealthshop[.]com, tjconsultingservices[.]com, and smartconnect[.]azurewebsites[.]net, used for command-and-control and tunneling.

Who’s being targeted

  • Commonly targeted roles: HR/Recruiting, Executives, Aerospace/Aviation staff, Defense program teams, Telecom employees, General workforce (phishing awareness).
  • Affected industries: Aerospace and aviation, Defense, Telecommunications, Government, Financial services.
  • Attack channels: email, website.
  • Impersonated: Trusted brand or hiring platform (recruitment brand impersonation), Video conferencing service (lookalike meeting page).

Red flags to watch for

  • Unexpected recruiting message that pressures you to open an archive or download files
  • Sender/brand looks legitimate but the link goes to a non-standard domain or third-party file-sharing site
  • Overly tailored message aimed at a specific person/role
  • Meeting link leads to a lookalike site (slightly misspelled/odd domain)
  • The “meeting” flow unexpectedly redirects to downloading an archive
  • File download is hosted on a third-party file-sharing service rather than the normal meeting platform
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is Mirage Kitten and who did it target?

Mirage Kitten is an espionage-focused threat group that ran highly targeted spear-phishing campaigns against organizations in government, aviation, telecom, and financial sectors across the Middle East and Africa.

How did the fake hiring lures work?

Attackers sent recruitment-themed messages impersonating trusted brands and hiring platforms, directing targets to portals that led to malicious archive downloads hosted on third-party file-sharing services.

What role did fake videoconferencing pages play?

Lookalike videoconferencing pages redirected victims away from a normal meeting flow toward malicious archives hosted on third-party file-sharing services, ultimately deploying malware.

Why were these lures effective despite being highly targeted?

The lures were highly tailored to specific individuals and roles, which made them appear more credible even though personalization does not indicate legitimacy.

Read the video transcript

You get an email: “Interview screening materials for your application.” Looks legit, big-name brand logo, tailored right to your role. Behind the scenes, this is Mirage Kitten: highly targeted spear‑phishing using fake recruitment portals and lookalike meeting pages that push malware archives from file‑sharing sites. Here’s the trap: the email says hiring portal, but the link quietly sends you to an odd domain or a fake video‑conferencing page, which then redirects again to a .zip on a random file‑sharing site. Your move: if a recruiting email or meeting link wants you to download a .zip, stop, don’t open it, forward it to security and confirm the request through a known, trusted contact.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026