Hackers Use Fake Coding Job Tests to Infect Developers With New Backdoors
Brief
Cybersecurity researchers have uncovered a targeted campaign in which hackers use fake software engineering tests to infect developers with previously undocumented remote access trojans (RATs) .
The activity has been attributed with high confidence to Mirage Kitten, an advanced persistent threat (APT) group known for targeting organizations in the Middle East and Africa.
The campaign abuses legitimate job-search platforms, including LinkedIn, to contact software engineers through fake recruiter profiles.
Victims are then directed to download coding challenges hosted on legitimate cloud infrastructure such as Amazon S3. The projects appear to be normal programming assessments but contain hidden malicious components.
Researchers identified two malware families, NodeRabbit and PollCat. Both are cross-platform RATs designed to run on Windows, Linux and macOS.
