Iran-linked cyber spies have been approaching technology specialists in aviation, aerospace and financial services with fabricated job opportunities that conceal previously unseen malware, according to recent findings from Kaspersky.
The cluster, which the Russian firm tracks as Mirage Kitten, has focused on developers and other technical staff in Egypt, Ethiopia and Afghanistan.
Contact typically begins on LinkedIn and similar professional platforms, where operators pose as recruiters for well-known technology companies and dangle apparently genuine openings.
Investigators identified two new malware families used in these operations: NodeRabbit and PollCat. Both are delivered as coding exercises that candidates are told to complete as part of the hiring process.
NodeRabbit functions as a remote-access trojan that can compromise Windows, Linux and macOS machines.
Once running, it gathers details about the victim and the infected host, creates or alters files, and executes further commands, giving operators ongoing control.
Kaspersky first observed NodeRabbit on a system in Afghanistan and later found related samples in Egypt and Ethiopia.
In a documented case, a software engineer was invited to download a technical assessment stored on Amazon cloud infrastructure and instructed to run the project at once.
One archive recovered in Afghanistan contained an application review task that had to be finished in three hours and explicitly prohibited the use of AI coding assistants.
Researchers believe the restriction was intended to stop automated tools from spotting the malicious code buried inside the project.
When the candidate launched the assignment, the hidden payload executed alongside the legitimate-looking work.
A parallel campaign used PollCat, another previously undocumented implant designed to maintain persistent access and fetch additional malicious files.
Targets in that wave were given only one hour to complete a programming test and required a short-lived six-digit code supplied by the supposed recruiter, increasing the pressure to open the package immediately.
The operators have also abused legitimate Microsoft Azure and Cloudflare services to hide their traffic.
In some instances they incorporated the name of the targeted organization into an Azure subdomain so that communications from an infected machine more closely resembled ordinary corporate activity.
Mirage Kitten, also known as UNC1549, Smoke Sandstorm and Nimbus Manticore, is assessed as an Iranian state-sponsored espionage group active since at least 2022.
Its latest victims align with an established emphasis on organizations in Africa and the Middle East, particularly those in aviation, aerospace and financial technology.
The same social engineering playbook—posing as recruiters and using fake job offers—has been employed in earlier campaigns against people working in sensitive industries across the region. The combination of professionally crafted lures, time-limited technical tests, and new cross-platform implants illustrates how the group continues to refine its methods while remaining focused on the same geographic and sectoral priorities.