CTIPilot
Wed · 02 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Wednesday, 2 September 2026

3 verified findings from 1 run · 4 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01A broken email-verification check on one identity provider let attackers silently bind to any Dropbox account with 2FA disabled. Dropbox confirmed to Reuters (2026-09-02) that unauthorized parties accessed roughly 5,000 accounts between 4 and 21 August 2026 by abusing its "Continue with Lenovo" single sign-on integration. Lenovo's own ID registration flow failed to verify that a registrant controlled the email address supplied, letting an attacker register a Lenovo ID under a victim's email with no access to that inbox; Dropbox then implicitly trusted the asserted email claim to bind a session to the matching account whenever that account had no two-factor authentication enabled.
  2. 02Bern almost handed a hyperscaler the register that verifies whether a Swiss digital identity is genuine. Investigative reporting by Republik (2026-09-01), corroborated by heise online and Inside IT Switzerland, reveals that Switzerland's Federal Office of Justice and Federal Office of Informatics planned in spring 2026 to award Amazon Web Services a contract covering core components of the Swiss E-ID's trust infrastructure. Justice Minister Beat Jans vetoed the award in mid-February 2026 on digital-sovereignty grounds, with one of the three outlets also tying the decision to Amazon's exposure under the US CLOUD Act; the Confederation's existing AWS framework contracts give Amazon unilateral rights to change technical terms and only a 90-day data-migration window on termination.
  3. 03An Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding challenge. Kaspersky's GReAT team documented (2026-09-01) two previously undocumented cross-platform RATs, NodeRabbit (Node.js) and PollCat (JavaScript), attributed with high confidence to Mirage Kitten, the Iran-nexus actor also tracked as Nimbus Manticore/UNC1549/Smoke Sandstorm. Both are delivered through fake LinkedIn recruiter personas offering timed technical-hiring assessments whose bundled npm package launches the implant on import. Confirmed victims are in fintech, aviation and aerospace in Egypt, Ethiopia and Afghanistan; no CVE is involved.

01Active threats, incidents & disclosures1 item

NOTABLENATOB1

Dropbox account takeover via a federated Lenovo-ID trust gap: roughly 5,000 accounts accessed with no password and no 2FA bypass needed

Dropbox confirmed to Reuters on 2026-09-02 that unauthorized parties accessed roughly 5,000 Dropbox accounts between 4 and 21 August 2026 by abusing "Continue with Lenovo," one of several third-party identity-provider login options Dropbox offers alongside Google and Apple (Reuters via Free Malaysia Today, 2026-09-02). The root cause is a broken trust chain spanning both parties. On Lenovo's side, the ID registration flow failed to verify that a registrant actually controlled the email address they supplied, so an attacker could register a brand-new Lenovo ID under a victim's known or guessed email address with no access to that inbox at all. On Dropbox's side, the relying-party logic then implicitly trusted the identity provider's asserted email claim to bind a login session to the matching Dropbox account (with no password prompt, no step-up challenge and no "link this new identity?" consent screen) whenever that account had Dropbox's own two-factor authentication disabled: "an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address" (Dropbox notification email, via 9to5Mac, 2026-09-01).

Once inside, attackers could browse account contents freely; per Dropbox, files were viewed or downloaded in fewer than a third of the roughly 5,000 affected accounts (heise Security, 2026-09-02). Reporting describes bulk, low-effort targeting rather than hand-picked victims, one reclaimed rogue Lenovo ID carried the throwaway display name "John Madden," the late NFL broadcaster (9to5Mac, 2026-09-01). Dropbox has since terminated every session authenticated via a Lenovo ID, severed the Lenovo–Dropbox account-linking integration entirely, and changed its system so a user's existing Dropbox password must now be entered before any Lenovo-ID-authenticated session can be established; it has reported the incident to data-protection regulators (Reuters via Free Malaysia Today, 2026-09-02). Lenovo separately confirmed the "legacy integration... could be used to improperly authenticate certain Dropbox accounts" and states its own customer accounts were not affected (Reuters via Free Malaysia Today, 2026-09-02).

Triage: a legitimate "Continue with Lenovo" (or any federated-IdP) login is ordinary traffic and is not distinguishable from this abuse pattern at the network layer, the discriminator lives in the relying party's own session and account-linking logs. The signal is a session established via a third-party IdP for an account that never previously had that IdP linked, immediately following a fresh registration on the IdP side, landing on an account with no second factor configured.

Dropbox told Reuters that it identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled, prompting the company to terminate all sessions authenticated through a Lenovo ID.

Reuters (via Free Malaysia Today) 2026-09-02

Lenovo identified a "legacy integration" between Lenovo ID and Dropbox that "could be used to improperly authenticate certain Dropbox accounts". The company said its own customers were not affected and that an investigation was ongoing.

Reuters (via Free Malaysia Today), quoting Lenovo

Dropbox partners with Lenovo as an identity provider so that users can log in to their Dropbox accounts using verified Lenovo IDs. While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo's email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address.

Dropbox, in its notification email to affected users (via 9to5Mac)

So konnte sich der Täter im Zeitraum 4. bis 21. August in rund 5.000 Dropbox-Konten frei umsehen. In weniger als einem Drittel der Fälle soll er Dateien gefunden haben, die ausreichend interessant erschienen, um sie herunterzuladen. (translated from German: The perpetrator was thus able to freely browse around 5,000 Dropbox accounts between 4 and 21 August. In fewer than a third of cases, they are said to have found files interesting enough to download.)

heise Security (Daniel AJ Sokolov)
incident02 Sep 05:20Zmulti-sourceOpen finding ↗

02Research, reports & policy1 item

NOTABLEupdatedNATOB2

Swiss federal offices planned to outsource part of the E-ID trust infrastructure to Amazon Web Services; a ministerial veto stopped it in February 2026 on CLOUD Act and digital-sovereignty grounds

Republik's investigation, published 2026-09-01, reveals that Switzerland's Federal Office of Justice (Bundesamt für Justiz) and Federal Office of Informatics and Telecommunications (BIT) planned in spring 2026 to award Amazon Web Services a contract covering core components of the Swiss E-ID's "Vertrauensinfrastruktur"; the trust infrastructure that confirms whether a digital identity is genuine and whether a requesting organization is authorized to verify it (Republik, 2026-09-01). The scope covered the Basisregister, which anonymously tracks whether a given E-ID is still valid, and the publicly queryable Vertrauensregister listing every authorized issuer and verifier, from federal, cantonal and communal authorities to private organizations such as banks. AWS was favored chiefly for its around-the-clock data-centre availability, which officials wanted as a fallback given delays in the Confederation's own planned government cloud; the Federal Office of Justice confirmed to Republik that "im Rahmen der Projektarbeiten wurden aus technischer Sicht sämtliche Optionen geprüft" (all options were reviewed from a technical standpoint as part of the project work, translated from German) (Republik, 2026-09-01).

Federal Councillor Beat Jans, the SP minister responsible for approving major federal IT procurements, vetoed the award in mid-February 2026: "an award to Amazon was out of the question," per Republik's sources close to the Federal Council, because handing the task to the American company would directly contradict the Federal Council's own objectives for greater Swiss digital sovereignty (Republik, 2026-09-01). The specific legal exposure behind that reasoning, per Inside IT's own relay of the same insider sourcing, is that Amazon as a US company is subject to the US CLOUD Act (Inside IT Switzerland, 2026-09-01); Republik's and heise's own reporting present the CLOUD Act point as their own explanatory framing rather than folding it into the insider-confirmed statement, so the sourcing on whether Jans's own confirmed rationale explicitly named the CLOUD Act, or only digital sovereignty in general, is not fully consistent across the three outlets. Republik's review of the Confederation's existing 2021 AWS framework contract (obtained after the outlet won a Federal Administrative Court case for disclosure) found a standardized commercial template rather than terms negotiated for state use: Amazon reserves the unilateral right to change the technical basis of the service, liability for outages is minimal, and on contract termination the administration has only 90 days to migrate all its data before Amazon irrevocably deletes it (Republik, 2026-09-01). An expert in decentralized trust architectures quoted by Republik frames the underlying risk independent of the vendor's home jurisdiction: "it becomes questionable when the state makes itself dependent, for critical infrastructure, on a single commercial provider that can discontinue operations, change terms, or impair availability" (translated from German) (Republik, 2026-09-01).

The E-ID's public launch is already delayed from end-2026 to the first half of 2027 for unrelated reasons, open questions on AHV-number lookups, AI-driven deepfake risk to online enrollment, and incompatibility with the EU's own eID system in its first version (Republik, 2026-09-01).

An award to Amazon was out of the question. (translated from German)

Republik 2026-09-01

It becomes questionable when the state makes itself dependent, for critical infrastructure, on a single commercial provider that can discontinue operations, change terms, or impair availability. (translated from German)

Republik, quoting Martina Kolpondinos (decentralized-trust-architecture expert)

If the cloud contract is terminated, the federal administration has only 90 days to withdraw its data before Amazon irrevocably deletes everything. (translated from German)

Republik 2026-09-01

In light of the latest developments in the field of artificial intelligence, security in the online issuance process for the E-ID is currently being further strengthened. In particular, through the use of additional technical safeguards, it should become harder to introduce malware onto end devices, and the detection of deepfakes should be strengthened.

Worth mentioning in particular are transparency through open source, the conducting of penetration tests, and bug bounty programmes.

Federal Office of Justice / eid.admin.ch (official) 2026-09-03
Updaterun 2026-09-05T0409Z-intelupdated_atsourcesevidencebody

At the 3 September 2026 meeting of the Advisory Council Digital Switzerland, chaired by Justice Minister Beat Jans with Federal Chancellor Viktor Rossi participating, the Federal Department of Justice and Police stated that security in the E-ID's online issuance process is currently being further strengthened in light of recent AI developments: "in particular, through the use of additional technical safeguards, it should become harder to introduce malware onto end devices, and the detection of deepfakes should be strengthened" (eid.admin.ch, 2026-09-03). The release, attributing the emphasis on learning from mistakes to Jans, names the programme's standing security controls as the mechanism for finding such gaps: "transparency through open source, the conducting of penetration tests, and bug bounty programmes" (eid.admin.ch, 2026-09-03). No technical specification of the "additional technical safeguards" (an attestation mechanism, device-integrity check or liveness-detection method) has been published; this is a policy-level commitment, not yet an implementation detail defenders can act on.

policy02 Sep 05:10Zsingle-sourceOpen finding ↗

03Updates to prior coverage4 items

HIGHupdatedNATOA1

France's tax authority cut the intruders' accounts in June and July and found no data theft, it took the criminal's sale listing two months later to establish that 678,000 records had already gone

First published 2026-08-15 · open finding →

Updaterun 2026-09-02T0411Z-intelentitiessourcesevidencebody

ZATAZ reported on 2026-08-07 that the actor Cybernox claimed, jointly with a second handle, to have leaked a database tied to Bloctel containing exactly 3,032,386 phone numbers, a claim matching DGCCRF's 2026-08-12 disclosure of a leak affecting roughly 3 million phone numbers, 600,000 of them Bloctel registrants, in both scale and timing. Neither DGCCRF nor ZATAZ confirms Cybernox as the actor behind the DGFiP-adjacent Bloctel incident; this is a plausible correlation, not a confirmed attribution.

A plausible, unconfirmed link has surfaced for the third breach this entry has so far declined to attribute. ZATAZ reported on 2026-08-07 (five days before DGCCRF's public warning) that an actor using the handle Cybernox, jointly with a second handle presented as "don't call me," claimed to have leaked a database tied to Bloctel, France's telemarketing opt-out registry, containing exactly 3,032,386 phone numbers (ZATAZ.COM, 2026-08-07). That figure and timing are consistent with DGCCRF's own disclosure of a leak affecting roughly 3 million phone numbers, 600,000 of them Bloctel registrants, taken via a fraudulently accessed professional account. ZATAZ's own reporting is explicit that this does not establish attribution: "these hacks must be treated as claims published by Cybernox. A line displayed on an underground forum does not demonstrate that an organization itself suffered a full intrusion" (translated from French) (ZATAZ.COM, 2026-08-07). Neither DGCCRF nor ZATAZ names Cybernox as the actor behind the DGFiP-adjacent Bloctel incident, so this entry records the correlation without upgrading it to attribution.

HIGHupdatedNATOA1

Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution

First published 2026-08-04 · open finding →

Updaterun 2026-09-02T0411Z-intelsourcesevidencebody

Switzerland's wealth-manager lobby (VSV) wrote to Justice Minister Beat Jans warning that the country's own incoming Transparency Register (covering roughly 500,000 beneficial owners and due live 1 October 2026) would be an "extremely attractive target for cyber criminals" given this breach, and asked for a delay or materially stricter access controls; the banking lobby (SBVg) separately raised the same concern. The Swiss Federal Council confirmed on 31 August 2026 it will proceed with the launch unchanged.

This breach has become the argument in a live Swiss policy fight over a comparable register. The Verband Schweizerischer Vermögensverwalter (VSV) wrote to Justice Minister Beat Jans warning that Switzerland's own incoming Transparency Register (covering roughly 500,000 beneficial owners, due live 1 October 2026) would be an "extremely attractive target for cyber criminals" (Inside Paradeplatz, 2026-08-31, citing the Financial Times' quotation of the letter), and asked for a delay or stricter access controls; the letter is dated 24 August 2026 and was seen by Reuters (Exxpress, citing Reuters wire, 2026-08-31). The Swiss Bankers Association (SBVg) separately raised the same concern. The Swiss Federal Council confirmed on 31 August 2026 that it will proceed with the 1 October launch unchanged, stating that various measures are planned to guarantee the "highest possible level of protection" (translated from German) (Exxpress, citing Reuters wire, 2026-08-31).

Unlike Liechtenstein's compromised portal, the Swiss register is designed to run inside a dedicated secured network of the Federal Department of Justice and Police, is an in-house Confederation build rather than an external vendor's system, and restricts direct database access to the operating office and a Federal Department of Finance control unit; external reporting parties reach it only through the EasyGov portal or a dedicated interface, the same portal-mediated access pattern that let the Liechtenstein attacker enumerate all 31,000 records one by one through a vulnerable reporting interface (Neue Zürcher Zeitung, 2026-08-07).

Defender takeaway (updated): for Swiss fiduciaries, trustees and banks, both jurisdictions' registers reach the same client population, so the 1 October go-live of the Swiss register adds a second authoritative identity-verification dataset attackers can draw on for the pretexting risk this entry already describes. The detection lesson carries over directly: a single reporting account exceeding its own historical query volume by orders of magnitude in one session is the signal to watch for on the Swiss register's EasyGov-mediated access path, portal-side rate limiting or not.

HIGHCVE-2026-19313 +4updatedNATOA2

WatchGuard Fireware OS: two pre-auth RCEs in the iked IKE/VPN daemon plus a pre-auth stack overflow in the deprecated Mobile Security epm service

First published 2026-08-31 · open finding →

Updaterun 2026-09-02T0411Z-intelcvesaffected_productstechniquesactionssummarysourcesevidencesourcing_note

NCSC-CH's advisory on the same 27 August bulletin adds two CVEs this entry had not covered: CVE-2026-19318, a third pre-auth stack overflow in the iked daemon that requires IKE payload diagnostic logging to be enabled, and CVE-2026-78174, a session-hijack flaw in the Dimension management platform where a low-privileged Dimension Administrator can extract a Super Administrator's session token from an unredacted diagnostic log. No exploitation reported for either.

NCSC Switzerland's advisory on the same 27 August bulletin, created 2026-09-01, adds two CVEs this entry had not covered. CVE-2026-19318 (CVSS 9.3) is a third pre-authentication stack overflow in iked's IKE_AUTH handling: an attacker who completes IKE_SA_INIT can send an IKE_AUTH message carrying an EAP-MSCHAPv2 payload with an undersized embedded length field, triggering the overflow, which WatchGuard's own advisory describes as causing "a crash and denial-of-service condition (with automatic respawn)," with "potential for remote code execution" given the attacker-influenced stack overwrite (WatchGuard PSIRT, 2026-08-27), the same hedged severity language WatchGuard uses for the two iked flaws already covered above. Unlike those two, exploitation here is conditional: it requires that IKE payload diagnostic logging, an operational troubleshooting setting not enabled by default, be turned on (WatchGuard PSIRT, 2026-08-27); a Firebox with diagnostic logging off is not exposed to this specific flaw.

CVE-2026-78174 (CVSS 9.3) is a different bug class on a different product: WatchGuard Dimension, the centralized reporting and management platform. Dimension's web UI diagnostic log records session identifiers for logged-in users unredacted; a low-privileged Dimension Administrator who retrieves that log can extract a Super Administrator's session token while the Super Administrator is logged in, then impersonate them fully, reaching Access Management, creating, deleting or altering any user or group, changing system-wide configuration, locking out legitimate administrators, and holding persistent full administrative control (WatchGuard PSIRT, 2026-08-27). Both flaws share the same fix cadence as the original three: Fireware OS 2026.3.1 / 2026.2.2 / 12.12.2 / 12.5.20 for CVE-2026-19318, Dimension 2.3.1 for CVE-2026-78174. WatchGuard reports no observed exploitation for either.

Defender takeaway (updated): the exposure decision for CVE-2026-19318 turns on whether IKE payload diagnostic logging is enabled; check that setting before assuming this flaw applies to a given appliance. For Dimension, treat diagnostic-log export or viewing as a privileged, logged action and audit which accounts have exercised it; patch to 2.3.1 regardless, since a compromised low-privileged Dimension Administrator account is now a path to full Super Administrator control.

CRITICALCVE-2026-82329exploitedupdatedNATOA2

CVE-2026-82329, JFrog Artifactory: an unauthenticated attacker gets administrative access under default configuration (CVSS 9.8)

First published 2026-09-01 · open finding →

Updaterun 2026-09-02T0411Z-intelcvestagstechniquesactionspriorityimmediate_actionsummarysourcesevidenceclassificationsourcing_note

CVE-2026-82329 has moved from disclosed to actively exploited within days of the patch. NCSC Switzerland's advisory and watchTowr's own Attacker Eye honeypot telemetry both record active exploitation, and watchTowr names the mechanism: a default "phantom" join key in JFrog Access lets an unauthenticated attacker forge access and mint administrator-level credentials, which attackers are now using to enumerate users, groups, credential sets and federated access topologies. Priority moves to critical given confirmed exploitation of a pre-auth path to full admin control of CI/CD supply-chain infrastructure.

CVE-2026-82329 has moved from disclosed to actively exploited. NCSC Switzerland's advisory, created 2026-09-01, records the current exploitation status as "Actively Exploited" (NCSC Switzerland Cyber Security Hub, 2026-09-01), and watchTowr's own telemetry independently caught the same activity: "this moved from disclosure to real-world exploitation with uncomfortable efficiency," per watchTowr's Yordan Ganchev (The Hacker News, 2026-09-01). Data from watchTowr's global Attacker Eye honeypot network shows attackers minting administrator tokens and enumerating users, groups, credential sets and federated access topologies (SecurityWeek, 2026-09-01). watchTowr names the mechanism: the flaw sits in JFrog Access, the component that issues and validates Artifactory credentials, and an instance with no additional join key configured receives a default "phantom" join key that an unauthenticated attacker can abuse to forge access and mint administrator-level credentials (The Hacker News, 2026-09-01), reconnaissance consistent with staging a software-supply-chain pivot into the binaries and containers Artifactory distributes downstream. As of 1 September, CISA had not yet added CVE-2026-82329 to its Known Exploited Vulnerabilities catalog (SecurityWeek, 2026-09-01).

Given confirmed active exploitation of a pre-auth, no-interaction path to full administrative control of a system that custodies CI/CD credentials and build artifacts, this entry's priority moves to critical.

Defender takeaway (updated): treat any unpatched, internet-reachable, self-hosted instance as already probed. Beyond patching, inspect Artifactory audit logs and JFrog Access logs for admin-scoped tokens minted with no preceding interactive admin login, review newly created or modified users, groups and permission targets, and rotate every credential the instance held.

04Deep dive1 item

NOTABLENATOB2

Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments

Kaspersky's GReAT team published an analysis on 2026-09-01 of two previously undocumented cross-platform remote access trojans it attributes with high confidence to Mirage Kitten, the Iran-nexus actor this store already tracks under the alias cluster Screening Serpens/UNC1549/Smoke Sandstorm/Nimbus Manticore (Kaspersky Securelist, 2026-09-01). NodeRabbit and PollCat are "the first publicly documented use of Node.js- and JavaScript-based malware by this APT group," a departure from its historically native C/C++/Go tooling delivered via DLL search-order hijacking (Kaspersky Securelist, 2026-09-01).

Delivery. A fake recruiter persona on a job-search platform invites a target (in one documented case a software engineer approached about an opening at an unnamed major technology company) to complete a technical assessment, directing them to a coding challenge hosted on Amazon S3 and pressuring them to download and run it immediately (T1566.003, T1204.002) (Kaspersky Securelist, 2026-09-01). The NodeRabbit archive gives candidates a three-hour window to review the application and fix defects in its frontend, and separately claims the actual malicious file, server.js, is bug-free and should not be modified (steering attention away from the one file the attackers altered) while banning AI-assisted review, which Kaspersky notes would likely have flagged the suspicious first-line import of an unknown package (Kaspersky Securelist, 2026-09-01); the PollCat archive is a one-hour, OTP-gated React "CTF" challenge. The malicious code sits in a locally bundled, never-registry-published npm package (colorized_terminal or pretty-log) imported by the assessment's own project files (Kaspersky Securelist, 2026-09-01), which launches the implant the moment the candidate runs the project.

NodeRabbit. Kaspersky documents three variants of increasing sophistication, first found on a system in Afghanistan and subsequently on systems in Egypt and Ethiopia (Kaspersky Securelist, 2026-09-01). v1 binds a TCP listener on 127.0.0.1:48739 purely as a single-instance check (if the port is already bound, the malware assumes another instance is running and exits) and reaches its actual command-and-control over three Azure-hosted HTTPS endpoints, trying each in turn on failure, with every request AES-256-GCM-encrypted (Kaspersky Securelist, 2026-09-01); on Windows it persists by cloning node.exe into a renamed GUI-subsystem binary and adding an HKCU\...\Run registry key that runs it against the dropped script, with Linux and macOS equivalents using a cron @reboot entry and a LaunchAgent respectively (T1547.001, T1053.003) (Kaspersky Securelist, 2026-09-01). v2 adds sandbox and analyst-detection checks (limited memory, low CPU count, short uptime, analyst-associated usernames or hostnames, known analysis tools) and, before terminating on a positive match, sends benign decoy HEAD requests to major consumer sites to look less suspicious (T1497) (Kaspersky Securelist, 2026-09-01); it also implements partial corporate-proxy support, checking proxy environment variables, Windows Internet Settings and PAC configuration, and tunnelling HTTPS C2 through HTTP CONNECT: it first attempts an unauthenticated connection, retries using URL-embedded basic credentials if that fails, and only then delegates NTLM/Negotiate challenges to curl.exe --proxy-anyauth (Kaspersky Securelist, 2026-09-01); its persistence masquerades as an Intel Driver & Support Assistant component and adds a scheduled task run daily at 10AM (T1053.005) (Kaspersky Securelist, 2026-09-01). v3, seen against a target in Ethiopia, grows the command set from 11 to 23: it adds harvesting of account addresses from Outlook OST/PST artifacts (T1114.001), a fake "GitHub Copilot Helper" VS Code extension for persistence that falls back to a current-user Run registry key even when no compatible extension directory exists (T1547.001), and Git post-merge/post-checkout hook injection, scanning up to 20 repositories under common project directories for one to inject into (Kaspersky Securelist, 2026-09-01).

PollCat. Distributed via the OTP-gated React "CTF" lure, PollCat is obfuscated JavaScript (T1027) that begins C2 registration before the victim completes the fake authentication step (Kaspersky Securelist, 2026-09-01). Kaspersky ties PollCat to Mirage Kitten partly through its structural overlap with a backdoor it tracks internally as Retrograde, which overlaps public reporting on the MiniFast family: the two follow a similar C2 handshake flow, share identical beacon timing defaults (120s beacon / 5s jitter / 60s retry) and share several command IDs, and NodeRabbit's own corporate-proxy NTLM/Negotiate delegation mirrors a technique Retrograde/MiniFast implements natively (Kaspersky Securelist, 2026-09-01).

Command and control. NodeRabbit's C2 requests are JSON objects wrapped in AES-256-GCM encryption (T1573.001); Kaspersky calls the combination of Azure Websites (AS8075, MarkMonitor-registered) and Cloudflare-backed domains for HTTPS C2 (T1071.001) a hallmark of Mirage Kitten's tradecraft observed across both NodeRabbit and PollCat (Kaspersky Securelist, 2026-09-01); in some cases the victim organization's own name is embedded in the Azure subdomain to blend with legitimate corporate traffic. Confirmed victims sit in fintech, aviation and aerospace organizations in Egypt, Ethiopia and Afghanistan, per both Kaspersky's own research and The Record's independent reporting (The Record, 2026-09-01); this fits Mirage Kitten's established Middle East/Africa targeting footprint. No CVE is involved; this is a social-engineering-plus-supply-chain delivery chain, not an exploited vulnerability.

Detection concepts. Lead with the telemetry class: process-creation events showing a Node.js runtime spawned from a freshly extracted archive or IDE "run project" action outside normal package-manager cache paths, followed by outbound HTTPS to *.azurewebsites.net or a newly registered domain, is the discriminating sequence. Persistence-artifact hunt: HKCU Run-key entries disguised as update tasks (e.g. naming patterns resembling browser or driver updaters) that execute a renamed Node binary against a .js payload; scheduled tasks invoking Node against a script under %APPDATA%, %LOCALAPPDATA% or ProgramData; VS Code extension directories containing an extension absent from the marketplace or lockfile inventory; and unexpected entries in .git/hooks/post-merge or post-checkout referencing an out-of-repository Node invocation.

Triage: legitimate take-home coding assessments are routine in technical hiring, so the assessment itself is not the signal. The discriminators are (a) a hard time limit or single-use access code paired with pressure to run the project immediately, (b) a first-line import of an unfamiliar or unpublished npm package bundled directly in node_modules rather than fetched from the registry, and (c) outbound network activity beginning before any of the project's advertised functionality has been exercised.

Hardening: for hiring workflows, run candidate submissions in disposable, network-egress-restricted sandboxes and never on a domain-joined workstation; for engineering teams generally, an EDR or application-control policy that flags Node processes launched from outside a version-controlled or package-manager-managed directory tree catches this delivery pattern independent of any specific package name.

NodeRabbit and PollCat represent the first publicly documented use of Node.js- and JavaScript-based malware by this APT group.

We attribute this activity to Mirage Kitten with a high degree of confidence based on the following observations

Kaspersky Securelist (GReAT) 2026-09-01
threat02 Sep 05:00Zsingle-sourceOpen finding ↗
Verification & coverage notes1 run

2026-09-02T0411Z-intel · Sonnet 5 · window 26 h · 3 entries published

Verification & coverage notes

Standard window (gap_hours=24.0, window_hours=26). No closed-source intake this run. Mechanical KEV sweep (tools/kev_window_diff.py) found zero in-window CISA KEV additions.

  • Runaway-duration note: total wall-clock (11217s, ~3.1h) exceeds the 3h threshold. Cause: the verification loop ran the full 8-iteration cap, each of the first seven iterations returned genuine truth/editorial findings (hallucinated facts, misattributions, a stale priority calibration, a classification miscalibration, and a workflow-internal-language leak that took two iterations to fully sweep), so no double-CLEAN confirmation was reached before the cap; iteration 8 (cap, fail-open) found three more low-confidence findings, applied post-hoc without a further confirmation pass per the documented cap rule. Research (Phase 1) and composition (Phase 4) were within normal bounds; the overrun is entirely attributable to the verification loop's iteration count, not a stall.

New entries (3): Mirage Kitten (Nimbus Manticore/UNC1549) debuts NodeRabbit/PollCat, its first Node.js/JavaScript implants, delivered via fake LinkedIn technical-hiring assessments (Kaspersky Securelist, this run's deep dive, notable); a policy entry on Switzerland's averted AWS outsourcing of part of the E-ID trust infrastructure, vetoed by Justice Minister Beat Jans in February 2026 on CLOUD Act/digital-sovereignty grounds and reported for the first time by Republik (notable); a Dropbox account takeover via a Lenovo-ID SSO trust gap affecting roughly 5,000 accounts, included on the transferable identity-federation-design lesson rather than home-region nexus (notable). Updates (4): CVE-2026-82329 (JFrog Artifactory) moves from disclosed to confirmed actively exploited, with watchTowr naming the "phantom" join-key mechanism; the WatchGuard Fireware/Dimension entry gains two further CVEs (a third iked pre-auth flaw gated on a non-default diagnostic-logging setting, and a Dimension session-hijack flaw) from a follow-up NCSC-CH advisory; the Liechtenstein VwbP breach entry gains a policy-fallout development, Swiss wealth-manager and banking lobbies pressed for a delay to the country's own Transparency Register, which the Federal Council confirmed on 31 August it will launch on schedule regardless; the DGFiP/Bloctel entry gains a plausible-but-unconfirmed actor correlation (Cybernox) for the previously unattributed Bloctel leak, resolving a standing coverage-backlog row.

  • Deep-dive selection: Mirage Kitten/NodeRabbit-PollCat clears criterion 3 (substantive new technical analysis with sufficient public detail to be actionable), three variants of increasing sophistication, a fully described delivery chain and C2 protocol, and a transferable hiring-pipeline hardening lesson. The rotation-demotion check looks at the prior 7 days only (2026-08-26 through 2026-09-01), and category apt-campaign was not used in that window (the three deep dives actually in that window are 2026-08-28 identity-infra, 2026-08-29 web-app-rce, 2026-08-31 cloud-saas), so no demotion applies; apt-campaign was used earlier in the wider 30-day lookback (2026-08-12, 2026-08-16), outside the 7-day window and so not relevant to this run's decision. This is the window's only deep dive.
  • borderline-drop: Bavaria's 2026 annual cybersecurity situation report, a subnational (Land-level) statistics-led report for a neighbouring but non-Swiss jurisdiction; its concrete numbers (ransomware +18% YoY, 48% of German KRITIS operators with no attack-detection system) are benchmarking colour rather than a Swiss-specific hunt/detect/patch decision, and the report itself leans on situational awareness rather than tradecraft. Dropped on the quality-over-quantity bar rather than published as a thin entry.
  • borderline-drop: Aesto Health third-party EHR-migration platform breach, 9.5M patients, US-only, no Swiss/EU nexus, no disclosed access vector or actor, and no ATT&CK-mappable behaviour stated by any source; fails the out-of-nexus breach gate on all four limbs.
  • Held for a later fire, not published (fails PD-6 as it stands): Krybit's leak-site claim against Geneva-headquartered UICC (Union for International Cancer Control), no victim statement, no Admiralty A/B journalism, only the leak-site listing itself. Added to state/coverage_backlog.md for re-check given the home-region nexus.
  • Coverage-backlog work this run: struck the DGFiP/Bloctel-Cybernox row (published as an update, hedged per the row's own instruction); advanced-but-not-struck rows for Boston Scientific (still no attacker attribution/vector, re-checked, no change), Insel Gruppe/ServiceNow (still paywalled, no corroboration found, re-checked, no change), and Ixa Systems SA/TheGentlemen (still uncorroborated, re-checked, no change; a new similarly-shaped Krybit/UICC row was opened instead of folded in, since it is a fresh in-window claim rather than a re-check); the Zurich court verdict row is not due until 2026-09-10 and got only a dated "untouched" note; the CVE-2026-16242 OpenShift row was checked against this run's KEV/CERT sweep (no fresh exploitation evidence or vendor bulletin found) and also carries a dated note; both remain open.
  • dedup: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats shares its actor entity with 2026-08-28/nimbus-manticore-twostroke-backdoor-europe, deliberate: distinct malware families (NodeRabbit/PollCat vs. the TWOSTROKE-like backdoor), distinct publisher, distinct delivery mechanism and distinct disclosure date, not a delta on the same finding.
  • Known pre-existing warning, not fixable this run: entries/2026-08-15/france-dgfip-tax-authority-credential-intrusion.md's 2026-08-21 changelog record's own summary field contains a pipeline self-reference ("this pipeline"). That field is part of an earlier fire's append-only changelog record and cannot be edited under the entry-lifecycle rule; the equivalent phrasing in the body's rendered ## Update section (which is revisable) was fixed as part of this run's own edit to that entry. Left for the quality audit to acknowledge.
  • Essential-coverage: all essential-tier sources across the four domains were attempted and reachable this run; no miss. cisa-advisories and cisa-directives remain on a long-standing persistent 403 with no other source indicating a new CISA directive in-window.
  • Registry hygiene: fixed a relation-direction error caught by the mechanical gate, uses relations belong on the actor/campaign/incident subject pointing to the tool object, not the reverse; moved the two new NodeRabbit/PollCat relations onto actor:screening-serpens-unc1549-smoke-sandstorm-nimbus-manticore-iran-apt.
  • Coverage gaps (quiet this run, no fetch failure beyond ssd-disclosure): govcert-at, infoguard-ch, oneconsult-ch, paradigm-shift-research, trellix, fox-it-blog, ico-uk, venarix, cnil-fr, ransom-isac (reachable, no in-window item).