Iran-linked APT Mirage Kitten is leveraging fake LinkedIn job recruitment tests to distribute malware families NodeRabbit and PollCat, with a particularly cunning social engineering angle that explicitly instructs candidates to avoid using AI tools during code review—likely to prevent automated detection of malicious payloads. This attack combines legitimate-seeming hiring practices with technical obfuscation to increase the likelihood that human reviewers will miss embedded threats. The tactic highlights how sophisticated threat actors are adapting social engineering techniques to circumvent both traditional and AI-powered security measures.
Kaspersky researchers have uncovered a new campaign by Mirage Kitten targeting aviation and financial technology organizations across the Middle East and Africa using previously undocumented malware families. The threat actor is deploying NodeRabbit, a Node.js-based malware, and PollCat, a JavaScript variant, marking an expansion of their known toolset against these critical sectors.
A Russian national extradited from Cyprus faces U.S. charges for orchestrating a malware distribution campaign between 2016 and 2017 using approximately 255 fraudulent accounts on a freelance platform. The suspect leveraged malicious Excel attachments to target around 80,000 platform users as part of the scheme. The defendant was arrested in Cyprus in May 2025 before being extradited to face prosecution in the Northern District of California.
A coordinated law enforcement operation supported by CrowdStrike and the Shadowserver Foundation has successfully sinkholed Sality, a long-running peer-to-peer botnet that infected over 15,000 machines globally since its emergence in 2003. The operation severed the botnet operators' control over all remaining infected systems, ending more than two decades of malicious activity. Sality originally propagated as a file-infecting virus that attached itself to executable programs before evolving into a widespread botnet threat.
A 23-year-old Sality P2P botnet has been disrupted through coordinated takedown efforts targeting its infrastructure and command channels. The operation employed peer list manipulation to disrupt the botnet's network communications and removed hosting for Sality payloads from the internet.