CTIPilot

NodeRabbit

tool · tool:noderabbit single-source

Cross-platform (Windows/Linux/macOS) Node.js remote access trojan delivered via trojanized npm packages (colorized_terminal, pretty-log) bundled inside fake LinkedIn/job-platform coding-challenge archives; three variants of increasing sophistication add sandbox evasion, a corporate-proxy fallback chain (unauthenticated attempt, then URL-embedded basic credentials, then NTLM/Negotiate delegation to curl.exe), and VS Code extension / Git-hook persistence with harvesting of account addresses from Outlook OST/PST artifacts. Attributed to Mirage Kitten/Nimbus Manticore with high confidence (Kaspersky Securelist, 2026-09-01).

Coverage timeline
1
first 2026-09-02 → last 2026-09-02
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
deep-dive
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
11
pinned v19.2 · see below

ATT&CK techniques

11 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566.003Phishing: Spearphishing via Service×1

Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Discovery TA0007

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Collection TA0009

T1114.001Email Collection: Local Email Collection×1

Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user’s local system, such as Outlook storage or cache files.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

T1573.001Encrypted Channel: Symmetric Cryptography×1

Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption algorithms use the same key for plaintext encryption and ciphertext decryption. Common symmetric encryption algorithms include AES, DES, 3DES, Blowfish, and RC4.

Evidence: 2026-09-02/mirage-kitten-noderabbit-pollcat-nodejs-rats · ATT&CK page ↗

Story timeline

  1. 2026-09-02Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments
    deep-diveAn Iranian espionage actor's first scripting-language implants arrive inside a timed take-home coding challenge

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

used by

Where this entity is cited

  • deep-dive1

Source distribution

  • securelist.com1 (50%)
  • therecord.media1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about NodeRabbit (1)

2026-09-02 · view entry permalink →

NOTABLENATOB2

Mirage Kitten (Nimbus Manticore/UNC1549) debuts Node.js and JavaScript RATs (NodeRabbit and PollCat) delivered through fake LinkedIn technical-hiring assessments

Kaspersky's GReAT team published an analysis on 2026-09-01 of two previously undocumented cross-platform remote access trojans it attributes with high confidence to Mirage Kitten, the Iran-nexus actor this store already tracks under the alias cluster Screening Serpens/UNC1549/Smoke Sandstorm/Nimbus Manticore (Kaspersky Securelist, 2026-09-01). NodeRabbit and PollCat are "the first publicly documented use of Node.js- and JavaScript-based malware by this APT group," a departure from its historically native C/C++/Go tooling delivered via DLL search-order hijacking (Kaspersky Securelist, 2026-09-01).

Delivery. A fake recruiter persona on a job-search platform invites a target (in one documented case a software engineer approached about an opening at an unnamed major technology company) to complete a technical assessment, directing them to a coding challenge hosted on Amazon S3 and pressuring them to download and run it immediately (T1566.003, T1204.002) (Kaspersky Securelist, 2026-09-01). The NodeRabbit archive gives candidates a three-hour window to review the application and fix defects in its frontend, and separately claims the actual malicious file, server.js, is bug-free and should not be modified (steering attention away from the one file the attackers altered) while banning AI-assisted review, which Kaspersky notes would likely have flagged the suspicious first-line import of an unknown package (Kaspersky Securelist, 2026-09-01); the PollCat archive is a one-hour, OTP-gated React "CTF" challenge. The malicious code sits in a locally bundled, never-registry-published npm package (colorized_terminal or pretty-log) imported by the assessment's own project files (Kaspersky Securelist, 2026-09-01), which launches the implant the moment the candidate runs the project.

NodeRabbit. Kaspersky documents three variants of increasing sophistication, first found on a system in Afghanistan and subsequently on systems in Egypt and Ethiopia (Kaspersky Securelist, 2026-09-01). v1 binds a TCP listener on 127.0.0.1:48739 purely as a single-instance check (if the port is already bound, the malware assumes another instance is running and exits) and reaches its actual command-and-control over three Azure-hosted HTTPS endpoints, trying each in turn on failure, with every request AES-256-GCM-encrypted (Kaspersky Securelist, 2026-09-01); on Windows it persists by cloning node.exe into a renamed GUI-subsystem binary and adding an HKCU\...\Run registry key that runs it against the dropped script, with Linux and macOS equivalents using a cron @reboot entry and a LaunchAgent respectively (T1547.001, T1053.003) (Kaspersky Securelist, 2026-09-01). v2 adds sandbox and analyst-detection checks (limited memory, low CPU count, short uptime, analyst-associated usernames or hostnames, known analysis tools) and, before terminating on a positive match, sends benign decoy HEAD requests to major consumer sites to look less suspicious (T1497) (Kaspersky Securelist, 2026-09-01); it also implements partial corporate-proxy support, checking proxy environment variables, Windows Internet Settings and PAC configuration, and tunnelling HTTPS C2 through HTTP CONNECT: it first attempts an unauthenticated connection, retries using URL-embedded basic credentials if that fails, and only then delegates NTLM/Negotiate challenges to curl.exe --proxy-anyauth (Kaspersky Securelist, 2026-09-01); its persistence masquerades as an Intel Driver & Support Assistant component and adds a scheduled task run daily at 10AM (T1053.005) (Kaspersky Securelist, 2026-09-01). v3, seen against a target in Ethiopia, grows the command set from 11 to 23: it adds harvesting of account addresses from Outlook OST/PST artifacts (T1114.001), a fake "GitHub Copilot Helper" VS Code extension for persistence that falls back to a current-user Run registry key even when no compatible extension directory exists (T1547.001), and Git post-merge/post-checkout hook injection, scanning up to 20 repositories under common project directories for one to inject into (Kaspersky Securelist, 2026-09-01).

PollCat. Distributed via the OTP-gated React "CTF" lure, PollCat is obfuscated JavaScript (T1027) that begins C2 registration before the victim completes the fake authentication step (Kaspersky Securelist, 2026-09-01). Kaspersky ties PollCat to Mirage Kitten partly through its structural overlap with a backdoor it tracks internally as Retrograde, which overlaps public reporting on the MiniFast family: the two follow a similar C2 handshake flow, share identical beacon timing defaults (120s beacon / 5s jitter / 60s retry) and share several command IDs, and NodeRabbit's own corporate-proxy NTLM/Negotiate delegation mirrors a technique Retrograde/MiniFast implements natively (Kaspersky Securelist, 2026-09-01).

Command and control. NodeRabbit's C2 requests are JSON objects wrapped in AES-256-GCM encryption (T1573.001); Kaspersky calls the combination of Azure Websites (AS8075, MarkMonitor-registered) and Cloudflare-backed domains for HTTPS C2 (T1071.001) a hallmark of Mirage Kitten's tradecraft observed across both NodeRabbit and PollCat (Kaspersky Securelist, 2026-09-01); in some cases the victim organization's own name is embedded in the Azure subdomain to blend with legitimate corporate traffic. Confirmed victims sit in fintech, aviation and aerospace organizations in Egypt, Ethiopia and Afghanistan, per both Kaspersky's own research and The Record's independent reporting (The Record, 2026-09-01); this fits Mirage Kitten's established Middle East/Africa targeting footprint. No CVE is involved; this is a social-engineering-plus-supply-chain delivery chain, not an exploited vulnerability.

Detection concepts. Lead with the telemetry class: process-creation events showing a Node.js runtime spawned from a freshly extracted archive or IDE "run project" action outside normal package-manager cache paths, followed by outbound HTTPS to *.azurewebsites.net or a newly registered domain, is the discriminating sequence. Persistence-artifact hunt: HKCU Run-key entries disguised as update tasks (e.g. naming patterns resembling browser or driver updaters) that execute a renamed Node binary against a .js payload; scheduled tasks invoking Node against a script under %APPDATA%, %LOCALAPPDATA% or ProgramData; VS Code extension directories containing an extension absent from the marketplace or lockfile inventory; and unexpected entries in .git/hooks/post-merge or post-checkout referencing an out-of-repository Node invocation.

Triage: legitimate take-home coding assessments are routine in technical hiring, so the assessment itself is not the signal. The discriminators are (a) a hard time limit or single-use access code paired with pressure to run the project immediately, (b) a first-line import of an unfamiliar or unpublished npm package bundled directly in node_modules rather than fetched from the registry, and (c) outbound network activity beginning before any of the project's advertised functionality has been exercised.

Hardening: for hiring workflows, run candidate submissions in disposable, network-egress-restricted sandboxes and never on a domain-joined workstation; for engineering teams generally, an EDR or application-control policy that flags Node processes launched from outside a version-controlled or package-manager-managed directory tree catches this delivery pattern independent of any specific package name.

NodeRabbit and PollCat represent the first publicly documented use of Node.js- and JavaScript-based malware by this APT group.

We attribute this activity to Mirage Kitten with a high degree of confidence based on the following observations

Kaspersky Securelist (GReAT) 2026-09-01
threat02 Sep 05:00Zsingle-sourceOpen finding ↗