🔍 Contexte

PubliĂ© le 1er septembre 2026 par Kaspersky (Securelist), cet article de recherche documente la dĂ©couverte de deux nouvelles familles de malwares attribuĂ©es Ă  Mirage Kitten (Ă©galement connu sous les noms UNC1549, Smoke Sandstorm, Nimbus Manticore), un groupe APT ciblant historiquement le Moyen-Orient et l’Afrique.

🎯 Vecteur d’accĂšs initial

La campagne repose sur une technique de faux recruteur (recruiter persona) sur LinkedIn et d’autres plateformes d’emploi. Les cibles reçoivent un lien vers une archive de dĂ©fi de codage trojanisĂ©e hĂ©bergĂ©e sur Amazon S3, prĂ©sentĂ©e comme une Ă©valuation technique pour un poste d’ingĂ©nieur. L’archive contient un projet Node.js lĂ©gitime (TaskFlow ou RankChallenge-react) dont un fichier source a Ă©tĂ© modifiĂ© pour importer un package npm malveillant (colorized_terminal ou pretty-log, version 2.1.0) bundlĂ© directement dans le rĂ©pertoire node_modules.

🐇 NodeRabbit RAT — Trois variantes

NodeRabbit est un RAT multiplateforme (Windows, Linux, macOS) écrit en Node.js. Trois variantes ont été identifiées :

  • Variante 1 (Afghanistan) : lancĂ©e via colorized_terminal, C2 sur Azure (plugplay, Rgbteller, Wslwebui), chiffrement AES-256-GCM, 11 commandes, persistance masquĂ©e en Microsoft Edge Update.
  • Variante 2 (Égypte) : lancĂ©e via pretty-log, anti-analyse (mĂ©moire, CPU, uptime, noms d’utilisateur suspects), support proxy NTLM/Negotiate via curl.exe, port TCP dĂ©rivĂ© de l’identifiant agent, persistance masquĂ©e en Intel DSA.
  • Variante 3 (Éthiopie) : lancĂ©e via pretty-log, 23 commandes dont outlook:emails, persist:vscode, persist:project:inject (Git hooks), C2 mixte Azure/Cloudflare, support WSL, fausse extension VS Code nommĂ©e GitHub Copilot Helper.

đŸ± PollCat RAT

PollCat est un RAT multiplateforme Ă©crit en JavaScript obfusquĂ©, distribuĂ© via un faux dĂ©fi React (RankChallenge-react). Il dĂ©marre indĂ©pendamment du processus d’authentification OTP. Il communique avec ses C2 (sahi-finance.com, GamebarAppinformation.azurewebsites.net, GamebarApp.azurewebsites.net) via des endpoints /beacon, /gate/hello, /gate/fetch, /gate/submit. Il dĂ©clare 22 commandes dont EVAL_JS, SYSTEM_CHECK, RUNDLL, CHUNKED_DOWNLOAD. La rĂ©ponse de handshake attendue est un HTTP 400 contenant un socketId.

đŸ—ïž Infrastructure

L’infrastructure C2 repose principalement sur Azure Websites (AS 8075, MarkMonitor) et des domaines Cloudflare (AS 13335, NameCheap). Les acteurs ont parfois intĂ©grĂ© le nom de l’organisation ciblĂ©e dans le sous-domaine Azure. Des domaines additionnels enregistrĂ©s entre mai et juillet 2026 ont Ă©tĂ© identifiĂ©s via des patterns d’infrastructure.

🎯 Victimologie

Victimes confirmĂ©es dans les secteurs FinTech et aviation/aĂ©rospatial en Égypte, Éthiopie et Afghanistan. Des soumissions d’archives malveillantes Ă  des scanners en ligne ont Ă©tĂ© dĂ©tectĂ©es depuis l’Inde, la Turquie, IsraĂ«l, l’Irak, l’Allemagne et l’Irlande.

🔗 Attribution

L’attribution Ă  Mirage Kitten repose sur des similaritĂ©s structurelles avec le backdoor natif Retrograde/MiniFast : handshake C2 identique (HTTP 400 comme succĂšs, socketId), endpoints similaires, timing de beacon identique (120 000 ms / 5 000 ms jitter), commandes partagĂ©es (dont REQUEST_ELEVATION 0xB0 et PERSIST 0xB1), et dĂ©lĂ©gation proxy NTLM via curl.exe.

📄 Nature de l’article

Il s’agit d’une publication de recherche technique de Kaspersky GReAT visant Ă  documenter une nouvelle campagne APT, ses TTPs, son infrastructure et ses IoCs pour permettre la dĂ©tection et le tracking par la communautĂ© CTI.

🧠 TTPs et IOCs dĂ©tectĂ©s

Acteurs de menace

  • Mirage Kitten (state-sponsored) —

TTP

  • T1566.002 — Phishing: Spearphishing Link (Initial Access)
  • T1195.002 — Supply Chain Compromise: Compromise Software Supply Chain (Initial Access)
  • T1059.007 — Command and Scripting Interpreter: JavaScript (Execution)
  • T1547.001 — Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
  • T1053.005 — Scheduled Task/Job: Scheduled Task (Persistence)
  • T1053.003 — Scheduled Task/Job: Cron (Persistence)
  • T1543.001 — Create or Modify System Process: Launch Agent (Persistence)
  • T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion)
  • T1027 — Obfuscated Files or Information (Defense Evasion)
  • T1497 — Virtualization/Sandbox Evasion (Defense Evasion)
  • T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
  • T1573.001 — Encrypted Channel: Symmetric Cryptography (Command and Control)
  • T1090 — Proxy (Command and Control)
  • T1105 — Ingress Tool Transfer (Command and Control)
  • T1083 — File and Directory Discovery (Discovery)
  • T1057 — Process Discovery (Discovery)
  • T1082 — System Information Discovery (Discovery)
  • T1016 — System Network Configuration Discovery (Discovery)
  • T1518.001 — Software Discovery: Security Software Discovery (Discovery)
  • T1114.001 — Email Collection: Local Email Collection (Collection)
  • T1005 — Data from Local System (Collection)
  • T1608.001 — Stage Capabilities: Upload Malware (Resource Development)
  • T1586.001 — Compromise Accounts: Social Media Accounts (Resource Development)
  • T1588.002 — Obtain Capabilities: Tool (Resource Development)

IOC

  • Domaines : oracle-challenge.s3.us-east-1.amazonaws.com — VT · URLhaus · ThreatFox
  • Domaines : naturalapplication.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : retaildemo.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : tubitak.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : rgbteller.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : wslwebui.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : plugplay.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : crossdwm.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : wdisystem.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : wslmenus.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : dnshnsdev.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : hpjumpsrv.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : storview.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : healthcomfsdpower.com — VT · URLhaus · ThreatFox
  • Domaines : visitfinancedentists.com — VT · URLhaus · ThreatFox
  • Domaines : kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : greenyjsgfd.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : helptellerbls.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : timedrv.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : userwellgtfs.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : msmanagementgrp.com — VT · URLhaus · ThreatFox
  • Domaines : msmanagementgrpmedia.com — VT · URLhaus · ThreatFox
  • Domaines : lifespotify.com — VT · URLhaus · ThreatFox
  • Domaines : gamebarapp.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : gamebarappinformation.azurewebsites.net — VT · URLhaus · ThreatFox
  • Domaines : sahi-finance.com — VT · URLhaus · ThreatFox
  • Domaines : healthful-hub.com — VT · URLhaus · ThreatFox
  • Domaines : neumedicahealthcare.com — VT · URLhaus · ThreatFox
  • Domaines : optimumhealthcredit.com — VT · URLhaus · ThreatFox
  • Domaines : healthfullyrecipes.com — VT · URLhaus · ThreatFox
  • Domaines : refreshhealthandwellness.com — VT · URLhaus · ThreatFox
  • Domaines : healthvitalitycare.com — VT · URLhaus · ThreatFox
  • Domaines : aceofspadesmanagement.com — VT · URLhaus · ThreatFox
  • Domaines : glmediaagency.com — VT · URLhaus · ThreatFox
  • Domaines : digimediaskill.com — VT · URLhaus · ThreatFox
  • Domaines : healthyweightplan.com — VT · URLhaus · ThreatFox
  • Domaines : mens-health-online.com — VT · URLhaus · ThreatFox
  • URLs : https://oracle-challenge.s3.us-east-1.amazonaws.com/Front-Technical-Challenge.zip — URLhaus
  • URLs : https://lifespotify.com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate — URLhaus
  • MD5 : 1EA83E4E4592B01E4ACAB63EB867BEE5 — VT · MalwareBazaar
  • MD5 : CBAAF0900A13F28E380F49ADECEC932C — VT · MalwareBazaar
  • MD5 : 366515822D5AC1CC500711EF57A2E32E — VT · MalwareBazaar
  • MD5 : CF449F1992C2819E62AC44A0B06AC2E7 — VT · MalwareBazaar
  • MD5 : E95A4366686E3F786EA3C056FAB5B0DA — VT · MalwareBazaar
  • MD5 : DE5AF16A3757EF700B01DC34D67079AE — VT · MalwareBazaar
  • MD5 : BE086789568441D0D7E4679AEE51F566 — VT · MalwareBazaar
  • MD5 : E259C5EDF158AAC4CFE14F77DDD0B196 — VT · MalwareBazaar
  • MD5 : 291AC3ABE73C5158E59A437B75D5F0AA — VT · MalwareBazaar
  • MD5 : 0962F56D7EC69F4F2A0162DCBE22116B — VT · MalwareBazaar
  • MD5 : 795E053A990A1569FFDCB57F48F6D085 — VT · MalwareBazaar
  • MD5 : 810F8E3B88EB05F710C09552941D6F56 — VT · MalwareBazaar
  • Fichiers : Front-Technical-Challenge.zip
  • Fichiers : FrontEnd-Task.zip
  • Fichiers : Task-FullStack.zip
  • Fichiers : fullstack-1536.zip
  • Fichiers : webapp76592.zip
  • Fichiers : webapp76531.zip
  • Fichiers : challenges-17831.zip
  • Fichiers : challenges-17832.zip
  • Fichiers : Project-1802.zip
  • Fichiers : Case-34234.zip
  • Fichiers : RankChallenge-react-6uJSX3-main.zip
  • Fichiers : colorized_terminal
  • Fichiers : pretty-log
  • Fichiers : server.js
  • Fichiers : requireObjects.js
  • Fichiers : index.js
  • Chemins : node_modules/.cache/.320697f1/index.js
  • Chemins : %APPDATA%\Microsoft\EdgeUpdate\msedge_update.js
  • Chemins : %LOCALAPPDATA%\Intel\DSA\idriver_support.js
  • Chemins : ~/.config/microsoft-edge-update/msedge_update.js
  • Chemins : ~/.config/intel-dsa/idriver_support.js
  • Chemins : ~/Library/Application Support/Intel DSA/idriver_support.js
  • Chemins : ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist
  • Chemins : ~/Library/LaunchAgents/com.intel.dsa.helper
  • Chemins : %APPDATA%\Microsoft\Network\requireObject.js
  • Chemins : ~/.node_packages
  • Chemins : ~/Library/LaunchAgents/com.harsh.requireobject.plist
  • Chemins : .git/hooks/post-merge
  • Chemins : .git/hooks/post-checkout
  • Chemins : .sv.json

⚠ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 1 septembre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© — contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • NodeRabbit (rat)
  • PollCat (rat)
  • Retrograde (backdoor)
  • MiniFast (backdoor)

🟱 Indice de vĂ©rification factuelle : 80/100 (haute)

  • ✅ securelist.com — source reconnue (liste interne) (20pts)
  • ✅ 37350 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 82 IOCs dont des hashes (15pts)
  • ⬜ 0/5 IOCs confirmĂ©s externellement (0pts)
  • ✅ 24 TTPs MITRE identifiĂ©es (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ✅ acteur(s) identifiĂ©(s) : Mirage Kitten (5pts)
  • ⬜ pas de CVE Ă  vĂ©rifier (0pts)

🔗 Source originale : https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/