đ Contexte
PubliĂ© le 1er septembre 2026 par Kaspersky (Securelist), cet article de recherche documente la dĂ©couverte de deux nouvelles familles de malwares attribuĂ©es Ă Mirage Kitten (Ă©galement connu sous les noms UNC1549, Smoke Sandstorm, Nimbus Manticore), un groupe APT ciblant historiquement le Moyen-Orient et l’Afrique.
đŻ Vecteur d’accĂšs initial
La campagne repose sur une technique de faux recruteur (recruiter persona) sur LinkedIn et d’autres plateformes d’emploi. Les cibles reçoivent un lien vers une archive de dĂ©fi de codage trojanisĂ©e hĂ©bergĂ©e sur Amazon S3, prĂ©sentĂ©e comme une Ă©valuation technique pour un poste d’ingĂ©nieur. L’archive contient un projet Node.js lĂ©gitime (TaskFlow ou RankChallenge-react) dont un fichier source a Ă©tĂ© modifiĂ© pour importer un package npm malveillant (colorized_terminal ou pretty-log, version 2.1.0) bundlĂ© directement dans le rĂ©pertoire node_modules.
đ NodeRabbit RAT â Trois variantes
NodeRabbit est un RAT multiplateforme (Windows, Linux, macOS) écrit en Node.js. Trois variantes ont été identifiées :
- Variante 1 (Afghanistan) : lancée via
colorized_terminal, C2 sur Azure (plugplay,Rgbteller,Wslwebui), chiffrement AES-256-GCM, 11 commandes, persistance masquĂ©e en Microsoft Edge Update. - Variante 2 (Ăgypte) : lancĂ©e via
pretty-log, anti-analyse (mĂ©moire, CPU, uptime, noms d’utilisateur suspects), support proxy NTLM/Negotiate viacurl.exe, port TCP dĂ©rivĂ© de l’identifiant agent, persistance masquĂ©e en Intel DSA. - Variante 3 (Ăthiopie) : lancĂ©e via
pretty-log, 23 commandes dontoutlook:emails,persist:vscode,persist:project:inject(Git hooks), C2 mixte Azure/Cloudflare, support WSL, fausse extension VS Code nommée GitHub Copilot Helper.
đ± PollCat RAT
PollCat est un RAT multiplateforme Ă©crit en JavaScript obfusquĂ©, distribuĂ© via un faux dĂ©fi React (RankChallenge-react). Il dĂ©marre indĂ©pendamment du processus d’authentification OTP. Il communique avec ses C2 (sahi-finance.com, GamebarAppinformation.azurewebsites.net, GamebarApp.azurewebsites.net) via des endpoints /beacon, /gate/hello, /gate/fetch, /gate/submit. Il dĂ©clare 22 commandes dont EVAL_JS, SYSTEM_CHECK, RUNDLL, CHUNKED_DOWNLOAD. La rĂ©ponse de handshake attendue est un HTTP 400 contenant un socketId.
đïž Infrastructure
L’infrastructure C2 repose principalement sur Azure Websites (AS 8075, MarkMonitor) et des domaines Cloudflare (AS 13335, NameCheap). Les acteurs ont parfois intĂ©grĂ© le nom de l’organisation ciblĂ©e dans le sous-domaine Azure. Des domaines additionnels enregistrĂ©s entre mai et juillet 2026 ont Ă©tĂ© identifiĂ©s via des patterns d’infrastructure.
đŻ Victimologie
Victimes confirmĂ©es dans les secteurs FinTech et aviation/aĂ©rospatial en Ăgypte, Ăthiopie et Afghanistan. Des soumissions d’archives malveillantes Ă des scanners en ligne ont Ă©tĂ© dĂ©tectĂ©es depuis l’Inde, la Turquie, IsraĂ«l, l’Irak, l’Allemagne et l’Irlande.
đ Attribution
L’attribution Ă Mirage Kitten repose sur des similaritĂ©s structurelles avec le backdoor natif Retrograde/MiniFast : handshake C2 identique (HTTP 400 comme succĂšs, socketId), endpoints similaires, timing de beacon identique (120 000 ms / 5 000 ms jitter), commandes partagĂ©es (dont REQUEST_ELEVATION 0xB0 et PERSIST 0xB1), et dĂ©lĂ©gation proxy NTLM via curl.exe.
đ Nature de l’article
Il s’agit d’une publication de recherche technique de Kaspersky GReAT visant Ă documenter une nouvelle campagne APT, ses TTPs, son infrastructure et ses IoCs pour permettre la dĂ©tection et le tracking par la communautĂ© CTI.
đ§ TTPs et IOCs dĂ©tectĂ©s
Acteurs de menace
- Mirage Kitten (state-sponsored) â
TTP
- T1566.002 â Phishing: Spearphishing Link (Initial Access)
- T1195.002 â Supply Chain Compromise: Compromise Software Supply Chain (Initial Access)
- T1059.007 â Command and Scripting Interpreter: JavaScript (Execution)
- T1547.001 â Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence)
- T1053.005 â Scheduled Task/Job: Scheduled Task (Persistence)
- T1053.003 â Scheduled Task/Job: Cron (Persistence)
- T1543.001 â Create or Modify System Process: Launch Agent (Persistence)
- T1036.005 â Masquerading: Match Legitimate Name or Location (Defense Evasion)
- T1027 â Obfuscated Files or Information (Defense Evasion)
- T1497 â Virtualization/Sandbox Evasion (Defense Evasion)
- T1071.001 â Application Layer Protocol: Web Protocols (Command and Control)
- T1573.001 â Encrypted Channel: Symmetric Cryptography (Command and Control)
- T1090 â Proxy (Command and Control)
- T1105 â Ingress Tool Transfer (Command and Control)
- T1083 â File and Directory Discovery (Discovery)
- T1057 â Process Discovery (Discovery)
- T1082 â System Information Discovery (Discovery)
- T1016 â System Network Configuration Discovery (Discovery)
- T1518.001 â Software Discovery: Security Software Discovery (Discovery)
- T1114.001 â Email Collection: Local Email Collection (Collection)
- T1005 â Data from Local System (Collection)
- T1608.001 â Stage Capabilities: Upload Malware (Resource Development)
- T1586.001 â Compromise Accounts: Social Media Accounts (Resource Development)
- T1588.002 â Obtain Capabilities: Tool (Resource Development)
IOC
- Domaines :
oracle-challenge.s3.us-east-1.amazonaws.comâ VT · URLhaus · ThreatFox - Domaines :
naturalapplication.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
retaildemo.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
tubitak.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
rgbteller.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
wslwebui.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
plugplay.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
crossdwm.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
wdisystem.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
wslmenus.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
dnshnsdev.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
hpjumpsrv.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
storview.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
healthcomfsdpower.comâ VT · URLhaus · ThreatFox - Domaines :
visitfinancedentists.comâ VT · URLhaus · ThreatFox - Domaines :
kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
greenyjsgfd.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
helptellerbls.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
timedrv.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
userwellgtfs.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
msmanagementgrp.comâ VT · URLhaus · ThreatFox - Domaines :
msmanagementgrpmedia.comâ VT · URLhaus · ThreatFox - Domaines :
lifespotify.comâ VT · URLhaus · ThreatFox - Domaines :
gamebarapp.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
gamebarappinformation.azurewebsites.netâ VT · URLhaus · ThreatFox - Domaines :
sahi-finance.comâ VT · URLhaus · ThreatFox - Domaines :
healthful-hub.comâ VT · URLhaus · ThreatFox - Domaines :
neumedicahealthcare.comâ VT · URLhaus · ThreatFox - Domaines :
optimumhealthcredit.comâ VT · URLhaus · ThreatFox - Domaines :
healthfullyrecipes.comâ VT · URLhaus · ThreatFox - Domaines :
refreshhealthandwellness.comâ VT · URLhaus · ThreatFox - Domaines :
healthvitalitycare.comâ VT · URLhaus · ThreatFox - Domaines :
aceofspadesmanagement.comâ VT · URLhaus · ThreatFox - Domaines :
glmediaagency.comâ VT · URLhaus · ThreatFox - Domaines :
digimediaskill.comâ VT · URLhaus · ThreatFox - Domaines :
healthyweightplan.comâ VT · URLhaus · ThreatFox - Domaines :
mens-health-online.comâ VT · URLhaus · ThreatFox - URLs :
https://oracle-challenge.s3.us-east-1.amazonaws.com/Front-Technical-Challenge.zipâ URLhaus - URLs :
https://lifespotify.com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validateâ URLhaus - MD5 :
1EA83E4E4592B01E4ACAB63EB867BEE5â VT · MalwareBazaar - MD5 :
CBAAF0900A13F28E380F49ADECEC932Câ VT · MalwareBazaar - MD5 :
366515822D5AC1CC500711EF57A2E32Eâ VT · MalwareBazaar - MD5 :
CF449F1992C2819E62AC44A0B06AC2E7â VT · MalwareBazaar - MD5 :
E95A4366686E3F786EA3C056FAB5B0DAâ VT · MalwareBazaar - MD5 :
DE5AF16A3757EF700B01DC34D67079AEâ VT · MalwareBazaar - MD5 :
BE086789568441D0D7E4679AEE51F566â VT · MalwareBazaar - MD5 :
E259C5EDF158AAC4CFE14F77DDD0B196â VT · MalwareBazaar - MD5 :
291AC3ABE73C5158E59A437B75D5F0AAâ VT · MalwareBazaar - MD5 :
0962F56D7EC69F4F2A0162DCBE22116Bâ VT · MalwareBazaar - MD5 :
795E053A990A1569FFDCB57F48F6D085â VT · MalwareBazaar - MD5 :
810F8E3B88EB05F710C09552941D6F56â VT · MalwareBazaar - Fichiers :
Front-Technical-Challenge.zip - Fichiers :
FrontEnd-Task.zip - Fichiers :
Task-FullStack.zip - Fichiers :
fullstack-1536.zip - Fichiers :
webapp76592.zip - Fichiers :
webapp76531.zip - Fichiers :
challenges-17831.zip - Fichiers :
challenges-17832.zip - Fichiers :
Project-1802.zip - Fichiers :
Case-34234.zip - Fichiers :
RankChallenge-react-6uJSX3-main.zip - Fichiers :
colorized_terminal - Fichiers :
pretty-log - Fichiers :
server.js - Fichiers :
requireObjects.js - Fichiers :
index.js - Chemins :
node_modules/.cache/.320697f1/index.js - Chemins :
%APPDATA%\Microsoft\EdgeUpdate\msedge_update.js - Chemins :
%LOCALAPPDATA%\Intel\DSA\idriver_support.js - Chemins :
~/.config/microsoft-edge-update/msedge_update.js - Chemins :
~/.config/intel-dsa/idriver_support.js - Chemins :
~/Library/Application Support/Intel DSA/idriver_support.js - Chemins :
~/Library/LaunchAgents/com.microsoft.edgeupdate.plist - Chemins :
~/Library/LaunchAgents/com.intel.dsa.helper - Chemins :
%APPDATA%\Microsoft\Network\requireObject.js - Chemins :
~/.node_packages - Chemins :
~/Library/LaunchAgents/com.harsh.requireobject.plist - Chemins :
.git/hooks/post-merge - Chemins :
.git/hooks/post-checkout - Chemins :
.sv.json
â ïž Ă propos de ces IOC â ils sont extraits automatiquement de l’article original le 1 septembre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© â contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- NodeRabbit (rat)
- PollCat (rat)
- Retrograde (backdoor)
- MiniFast (backdoor)
đą Indice de vĂ©rification factuelle : 80/100 (haute)
- â securelist.com â source reconnue (liste interne) (20pts)
- â 37350 chars â texte complet (fulltext extrait) (15pts)
- â 82 IOCs dont des hashes (15pts)
- ⏠0/5 IOCs confirmés externellement (0pts)
- â 24 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- â acteur(s) identifiĂ©(s) : Mirage Kitten (5pts)
- ⏠pas de CVE à vérifier (0pts)
đ Source originale : https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/