CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Screening Serpens

actor · actor:screening-serpens-unc1549-smoke-sandstorm-nimbus-manticore-iran-apt single-source

Iranian APT operationalising AppDomainManager hijacking; deployed six new RAT variants (MiniUpdate / MiniJunk V2) between February and April 2026. Kaspersky, which tracks the group as Mirage Kitten and states that equivalence itself, describes it as focused on aerospace, aviation, defence and telecommunications espionage across the Middle East and Africa, and in July 2026 documented a new toolset comprising the NightLedger backdoor and the BridgeHead and ArcBridge WebSocket tunnelers (Kaspersky Securelist, 2026-07-28).

Aliases: UNC1549, Smoke Sandstorm, Nimbus Manticore, Mirage Kitten

Coverage
4
first 2026-05-23 → last 2026-09-02
Latest activity
2026-09-02
An Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding…
Peak priority
high
2 high · 2 notable
Targets
telco
sectors: telco, aviation, finance · regions: middle-east, africa, europe
Sources cited
8
7 hosts
2026-05-234 appearances2026-09-02

Defender insights

What each entry about Screening Serpens tells a defender to do, newest first.

2026-09-02NOTABLEAn Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding challenge

Triage · detection

2026-08-28HIGHAn Iranian espionage actor already tracked for aerospace and telecom targeting adds a new backdoor and materially widens its named European footprint

Triage

2026-07-29NOTABLEKaspersky documents an Iran-nexus toolset that loads under a legitimate vendor binary via RPC delay-load and tunnels out through authenticated proxies

Triage

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

uses

Story timeline

  1. 2026-09-02Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments
    deep-diveAn Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding challenge
  2. 2026-08-28Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and Belarus
    active-threatsAn Iranian espionage actor already tracked for aerospace and telecom targeting adds a new backdoor and materially widens its named European footprint
  3. 2026-07-29Mirage Kitten (UNC1549) fields the NightLedger backdoor and two WebSocket tunnelers, one of them built to negotiate through corporate proxies with the victim's own SSO
    active-threatsKaspersky documents an Iran-nexus toolset that loads under a legitimate vendor binary via RPC delay-load and tunnels out through authenticated proxies
  4. 2026-05-23Unit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six new RATs
    researchUnit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six
ATT&CK techniques (21 across 9 tactics)

21 techniques observed across 4 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissancePhishing for Information: Spearphishing Link
  • Initial AccessPhishing: Spearphishing via Service
  • ExecutionScheduled Task/Job: Cron · Scheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: JavaScript · User Execution: Malicious File · Hijack Execution Flow: DLL · Hijack Execution Flow: Path Interception by Search Order Hijacking · Hijack Execution Flow: AppDomainManager
  • PersistenceScheduled Task/Job: Cron · Scheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationScheduled Task/Job: Cron · Scheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • StealthObfuscated Files or Information · Virtualization/Sandbox Evasion · Hijack Execution Flow: DLL · Hijack Execution Flow: Path Interception by Search Order Hijacking · Hijack Execution Flow: AppDomainManager
  • DiscoverySystem Network Configuration Discovery · Process Discovery · System Information Discovery · Virtualization/Sandbox Evasion
  • CollectionScreen Capture · Email Collection: Local Email Collection
  • Command and ControlApplication Layer Protocol: Web Protocols · Proxy · Protocol Tunneling · Encrypted Channel: Symmetric Cryptography

Reconnaissance TA0043

T1598.003Phishing for Information: Spearphishing Link×1

Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into divulging information, frequently credentials or other actionable information. Spearphishing for information frequently involves social engineering techniques, such as posing as a source with a reason to collect information (ex: Establish Accounts or Compromise Accounts) and/or sending multiple, seemingly urgent messages.

Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

Initial Access TA0001

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×2

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×3

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1574.008Hijack Execution Flow: Path Interception by Search Order Hijacking×1

Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program.

Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1574.014Hijack Execution Flow: AppDomainManager×1

Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.

Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×2

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×2

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×2

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×3

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1574.008Hijack Execution Flow: Path Interception by Search Order Hijacking×1

Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs. Because some programs do not call other programs using the full path, adversaries may place their own file in the directory where the calling program is located, causing the operating system to launch their malicious software at the request of the calling program.

Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

T1574.014Hijack Execution Flow: AppDomainManager×1

Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies. The .NET framework uses the `AppDomainManager` class to create and manage one or more isolated runtime environments (called application domains) inside a process to host the execution of .NET applications. Assemblies (`.exe` or `.dll` binaries compiled to run as .NET code) may be loaded into an application domain as executable code.

Evidence: 2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim · ATT&CK page ↗

Discovery TA0007

T1016System Network Configuration Discovery×1

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.

Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1057Process Discovery×1

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Collection TA0009

T1113Screen Capture×1

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1114.001Email Collection: Local Email Collection×1

Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×3

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1090Proxy×2

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1572Protocol Tunneling×2

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-08-28/nimbus-manticore-twostroke-backdoor-europe · 2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers · ATT&CK page ↗

T1573.001Encrypted Channel: Symmetric Cryptography×1

Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Entries about Screening Serpens (4)

2026-09-02 · view entry permalink →

NOTABLENATOB2

Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments

Kaspersky's GReAT team published an analysis on 2026-09-01 of two previously undocumented cross-platform remote access trojans it attributes with high confidence to Mirage Kitten, the Iran-nexus actor this store already tracks under the alias cluster Screening Serpens/UNC1549/Smoke Sandstorm/Nimbus Manticore (Kaspersky Securelist, 2026-09-01). NodeRabbit and PollCat are "the first publicly documented use of Node.js- and JavaScript-based malware by this APT group," a departure from its historically native C/C++/Go tooling delivered via DLL search-order hijacking (Kaspersky Securelist, 2026-09-01).

Delivery. A fake recruiter persona on a job-search platform invites a target (in one documented case a software engineer approached about an opening at an unnamed major technology company) to complete a technical assessment, directing them to a coding challenge hosted on Amazon S3 and pressuring them to download and run it immediately (T1566.003, T1204.002) (Kaspersky Securelist, 2026-09-01). The NodeRabbit archive gives candidates a three-hour window to review the application and fix defects in its frontend, and separately claims the actual malicious file, server.js, is bug-free and should not be modified (steering attention away from the one file the attackers altered) while banning AI-assisted review, which Kaspersky notes would likely have flagged the suspicious first-line import of an unknown package (Kaspersky Securelist, 2026-09-01); the PollCat archive is a one-hour, OTP-gated React "CTF" challenge. The malicious code sits in a locally bundled, never-registry-published npm package (colorized_terminal or pretty-log) imported by the assessment's own project files (Kaspersky Securelist, 2026-09-01), which launches the implant the moment the candidate runs the project.

NodeRabbit. Kaspersky documents three variants of increasing sophistication, first found on a system in Afghanistan and subsequently on systems in Egypt and Ethiopia (Kaspersky Securelist, 2026-09-01). v1 binds a TCP listener on 127.0.0.1:48739 purely as a single-instance check (if the port is already bound, the malware assumes another instance is running and exits) and reaches its actual command-and-control over three Azure-hosted HTTPS endpoints, trying each in turn on failure, with every request AES-256-GCM-encrypted (Kaspersky Securelist, 2026-09-01); on Windows it persists by cloning node.exe into a renamed GUI-subsystem binary and adding an HKCU\...\Run registry key that runs it against the dropped script, with Linux and macOS equivalents using a cron @reboot entry and a LaunchAgent respectively (T1547.001, T1053.003) (Kaspersky Securelist, 2026-09-01). v2 adds sandbox and analyst-detection checks (limited memory, low CPU count, short uptime, analyst-associated usernames or hostnames, known analysis tools) and, before terminating on a positive match, sends benign decoy HEAD requests to major consumer sites to look less suspicious (T1497) (Kaspersky Securelist, 2026-09-01); it also implements partial corporate-proxy support, checking proxy environment variables, Windows Internet Settings and PAC configuration, and tunnelling HTTPS C2 through HTTP CONNECT: it first attempts an unauthenticated connection, retries using URL-embedded basic credentials if that fails, and only then delegates NTLM/Negotiate challenges to curl.exe --proxy-anyauth (Kaspersky Securelist, 2026-09-01); its persistence masquerades as an Intel Driver & Support Assistant component and adds a scheduled task run daily at 10AM (T1053.005) (Kaspersky Securelist, 2026-09-01). v3, seen against a target in Ethiopia, grows the command set from 11 to 23: it adds harvesting of account addresses from Outlook OST/PST artifacts (T1114.001), a fake "GitHub Copilot Helper" VS Code extension for persistence that falls back to a current-user Run registry key even when no compatible extension directory exists (T1547.001), and Git post-merge/post-checkout hook injection, scanning up to 20 repositories under common project directories for one to inject into (Kaspersky Securelist, 2026-09-01).

PollCat. Distributed via the OTP-gated React "CTF" lure, PollCat is obfuscated JavaScript (T1027) that begins C2 registration before the victim completes the fake authentication step (Kaspersky Securelist, 2026-09-01). Kaspersky ties PollCat to Mirage Kitten partly through its structural overlap with a backdoor it tracks internally as Retrograde, which overlaps public reporting on the MiniFast family: the two follow a similar C2 handshake flow, share identical beacon timing defaults (120s beacon / 5s jitter / 60s retry) and share several command IDs, and NodeRabbit's own corporate-proxy NTLM/Negotiate delegation mirrors a technique Retrograde/MiniFast implements natively (Kaspersky Securelist, 2026-09-01).

Command and control. NodeRabbit's C2 requests are JSON objects wrapped in AES-256-GCM encryption (T1573.001); Kaspersky calls the combination of Azure Websites (AS8075, MarkMonitor-registered) and Cloudflare-backed domains for HTTPS C2 (T1071.001) a hallmark of Mirage Kitten's tradecraft observed across both NodeRabbit and PollCat (Kaspersky Securelist, 2026-09-01); in some cases the victim organization's own name is embedded in the Azure subdomain to blend with legitimate corporate traffic. Confirmed victims sit in fintech, aviation and aerospace organizations in Egypt, Ethiopia and Afghanistan, per both Kaspersky's own research and The Record's independent reporting (The Record, 2026-09-01); this fits Mirage Kitten's established Middle East/Africa targeting footprint. No CVE is involved; this is a social-engineering-plus-supply-chain delivery chain, not an exploited vulnerability.

Detection concepts. Lead with the telemetry class: process-creation events showing a Node.js runtime spawned from a freshly extracted archive or IDE "run project" action outside normal package-manager cache paths, followed by outbound HTTPS to *.azurewebsites.net or a newly registered domain, is the discriminating sequence. Persistence-artifact hunt: HKCU Run-key entries disguised as update tasks (e.g. naming patterns resembling browser or driver updaters) that execute a renamed Node binary against a .js payload; scheduled tasks invoking Node against a script under %APPDATA%, %LOCALAPPDATA% or ProgramData; VS Code extension directories containing an extension absent from the marketplace or lockfile inventory; and unexpected entries in .git/hooks/post-merge or post-checkout referencing an out-of-repository Node invocation.

Triage: legitimate take-home coding assessments are routine in technical hiring, so the assessment itself is not the signal. The discriminators are (a) a hard time limit or single-use access code paired with pressure to run the project immediately, (b) a first-line import of an unfamiliar or unpublished npm package bundled directly in node_modules rather than fetched from the registry, and (c) outbound network activity beginning before any of the project's advertised functionality has been exercised.

Hardening: for hiring workflows, run candidate submissions in disposable, network-egress-restricted sandboxes and never on a domain-joined workstation; for engineering teams generally, an EDR or application-control policy that flags Node processes launched from outside a version-controlled or package-manager-managed directory tree catches this delivery pattern independent of any specific package name.

NodeRabbit and PollCat represent the first publicly documented use of Node.js- and JavaScript-based malware by this APT group.

We attribute this activity to Mirage Kitten with a high degree of confidence based on the following observations

Kaspersky Securelist (GReAT) 2026-09-01
threat02 Sep 05:00Zsingle-sourceOpen finding →

2026-08-28 · view entry permalink →

HIGHNATOB2

Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and Belarus

Group-IB documents new infrastructure and a new toolset for Nimbus Manticore, the Iranian, IRGC-affiliated actor also tracked as Screening Serpens, UNC1549, Smoke Sandstorm and Mirage Kitten (Group-IB itself uses "Tortoiseshell"). This is the third distinct toolset refresh reported for this actor within roughly seven months: six new RAT variants (MiniUpdate/MiniJunk V2) via AppDomainManager hijacking February–April 2026 (Unit 42), the NightLedger backdoor with BridgeHead/ArcBridge WebSocket tunnelers documented by Kaspersky in July 2026 (Kaspersky Securelist, 2026-07-28), and now (reported by Group-IB on 2026-08-26) a new reverse SSH tunneling utility and a TWOSTROKE-family C++ backdoor.

The SSH tunneler establishes an SSH connection to operator infrastructure over port 443, blending with normal HTTPS-port egress filtering, to set up a reverse tunnel. Group-IB writes that "Execution of this command establishes an SSH connection to the operator’s infrastructure" and does so "on port 443 to set up a reverse tunnel", so that traffic sent to a local port "on the C2 server is redirected back through the tunnel directly into the compromised network" (Group-IB, 2026-08-26), giving the operator interactive network access into the victim environment without an inbound listener on the victim side. The TWOSTROKE-like backdoor masquerades as the Windows Terminal Server SDK DLL (wtsapi32.dll), forward-exporting all legitimate SDK functions so that a legitimate executable loading it via DLL search-order hijacking continues to function normally while the backdoor executes alongside it: "masquerading as the Windows terminal server SDK DLL (wtsapi32.dll), this backdoor forward-exports all legitimate SDK functions. It appears to be designed for DLL search-order hijacking, tricking legitimate executables into loading the backdoor" (Group-IB, 2026-08-26). It encrypts stack strings, derives a unique per-victim identifier from the device hostname, and communicates with multiple hardcoded control servers over HTTPS.

Group-IB's infrastructure analysis, based on geographically-labeled subdomain naming conventions, indicates expanded targeting into European nations specifically named as the UK, France, Albania and Belarus, alongside continued Middle Eastern targeting: "the group's infrastructure and targeting profile span across countries in Europe and the Middle East. Specific targets include European nations such as the UK, France, Albania, and Belarus, alongside Middle Eastern regions including Israel, Turkey, and GCC member states" (Group-IB, 2026-08-26), a materially widened European footprint for an actor consistently reported as espionage-focused on aerospace, aviation, defence and telecommunications.

Triage: monitor for HTTPS-port (443) outbound connections that establish long-lived reverse-tunnel-shaped traffic patterns (asymmetric, low-volume-but-persistent bidirectional flows distinct from normal web-browsing HTTPS) and audit environments for a wtsapi32.dll present outside its expected system path or with a hash that does not match the legitimate Windows SDK component; the actor's own choice of a legitimate SDK DLL name is itself the detection anchor, since a genuine wtsapi32.dll never appears outside System32.

Execution of this command establishes an SSH connection to the operator’s infrastructure

on port 443 to set up a reverse tunnel.

on the C2 server is redirected back through the tunnel directly into the compromised network.

Masquerading as the Windows terminal server SDK DLL (wtsapi32.dll), this backdoor forward-exports all legitimate SDK functions. It appears to be designed for DLL search-order hijacking, tricking legitimate executables into loading the backdoor.

The group's infrastructure and targeting profile span across countries in Europe and the Middle East. Specific targets include European nations such as the UK, France, Albania, and Belarus, alongside Middle Eastern regions including Israel, Turkey, and GCC member states.

Group-IB 2026-08-26

Builds on: Unit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore)… · Kaspersky documents an Iran-nexus toolset that loads under a legitimate vendor binary via RPC…

threat28 Aug 06:20Zsingle-sourceOpen finding →

2026-07-29 · view entry permalink →

NOTABLENATOB2

Mirage Kitten (UNC1549) fields the NightLedger backdoor and two WebSocket tunnelers, one of them built to negotiate through corporate proxies with the victim's own SSO

The load-bearing detail in Kaspersky's write-up is not the backdoor's feature list but how it gets to run and how it gets out. NightLedger ships as a file named to impersonate SspiCli.dll and is placed alongside a legitimate AppVShNotify.exe; that binary does not import SspiCli.dll directly, but it does import RPCRT4.dll, which delay-loads SspiCli.dll at the moment it invokes an RPC API requiring authentication, so the malicious module is pulled in through the normal search order, under a legitimate vendor process, and forwards the expected exports to the genuine DLL so the host keeps functioning (Kaspersky Securelist, 2026-07-28). Two properties make this awkward to catch: the load is triggered by ordinary RPC activity rather than by anything the malware does, and because exports are proxied there is no crash or functional break to notice. The backdoor beacons over HTTPS and dispatches 16 numeric commands, among them process execution, identity and host/network reconnaissance, process listing and termination, directory and drive enumeration, file copy, deletion, upload and download, screenshot capture, DLL loading, beacon-interval changes, and collection of the Windows domain-join diagnostic log, which Kaspersky describes as a diagnostic log generated during domain and workgroup join, unjoin and related network-setup operations (Kaspersky Securelist, 2026-07-28). Kaspersky attributes NightLedger to Mirage Kitten on code and behavioural similarity to the group's historical implants, and observes that its command dispatch resembles TWOSTROKE, an implant previously documented as the same actor's (Kaspersky Securelist, 2026-07-28).

The tunnelers are the part worth a hunt cycle, and the two are not equivalent. Kaspersky describes ArcBridge as the simpler tool: a WebSocket-style channel with an embedded configuration block carrying C2 host, port, a retry value, an SSL flag and a likely implant identifier, driven by two commands, one to open a tunnel session and one to resolve a hostname (Kaspersky Securelist, 2026-07-28). BridgeHead is the one built for networks that do not simply let traffic out: presented with an HTTP 407 proxy-authentication challenge it queries which schemes the proxy supports, selects Negotiate in preference to NTLM, supplies null credentials so Windows fills in the logged-in user's single-sign-on context, and retries, falling back to exponential connection retry capped at a minute when that fails (Kaspersky Securelist, 2026-07-28). The consequence for defenders is that the outbound channel authenticates as a real employee to the real proxy, so it appears in proxy logs as that user's traffic. Once established, the operator drives everything server-side and the implant only forwards, which Kaspersky describes as turning the host into a relay node so that resulting TCP traffic appears to originate inside the victim's network (Kaspersky Securelist, 2026-07-28). BridgeHead also refuses to run outside its intended target: a hardcoded 3-character value must appear as a substring of the lowercased Windows username, and the implant exits silently otherwise, behaviour Kaspersky reads as evidence of prior internal reconnaissance and per-target tailoring of each binary (Kaspersky Securelist, 2026-07-28). Victims span government and SMB environments in Jordan and Tanzania, aviation in Pakistan, telecommunications in Ethiopia, finance in Burkina Faso and organisations in Egypt (Kaspersky Securelist, 2026-07-28).

Triage: AppVShNotify.exe loading SspiCli.dll is normal and expected, the parent process, the module name and the RPC trigger are all legitimate, so none of them discriminates on its own. The signal is the loaded file's identity: SspiCli.dll resolving from the same directory as the executable rather than from the system directory, and not carrying a valid Microsoft signature. On the network side, an authenticated proxy session that upgrades to a long-lived WebSocket and then carries a sustained, bidirectional flow to a single destination is the shape to look for; ordinary user browsing through the same proxy does not hold one connection open as a steady tunnel.

The implant masquerades as SspiCli.dll and appears to be designed for DLL search-order hijacking, targeting a legitimate AppVShNotify.exe binary. While AppVShNotify.exe does not directly import SspiCli.dll, it imports RPCRT4.dll, which can delay-load SspiCli.dll when it invokes an RPC API that requires authentication.

Still, it implements the same technique of limiting execution to a specific username on the infected machine by hardcoding a 3-character control value that must appear as a substring in the lowercased Windows username retrieved via GetUserNameA. If the match fails, the implant silently exits, confirming per-target tailoring of each deployed binary.

According to our telemetry, we identified victims across Middle East and African countries including Egypt, SMB and government environments in Jordan and Tanzania, aviation organizations in Pakistan, telecommunication companies in Ethiopia and financial-sector entities in Burkina Faso.

Kaspersky Securelist (GReAT) 2026-07-28
threat29 Jul 05:30Zsingle-sourceOpen finding →

Earlier coverage (1)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats2
  • Research1
  • Deep dive1

Source distribution

  • securelist.com2 (25%)
  • cybersecuritydive.com1 (12%)
  • group-ib.com1 (12%)
  • research.checkpoint.com1 (12%)
  • thehackernews.com1 (12%)
  • therecord.media1 (12%)
  • unit42.paloaltonetworks.com1 (12%)