Iranian Hackers Target Job Seekers on LinkedIn with Malicious Code
A new cyber campaign, attributed to an Iran-linked hacking group known as Mirage Kitten, is exploiting the job search process on LinkedIn to infiltrate victims' computers. The attackers pose as recruiters and offer software development roles, particularly in aviation and fintech. Instead of a traditional interview, candidates are asked to download and run code as part of a "home assignment." This code, however, can grant attackers access to the user's computer.
Israel is among the targeted countries, alongside Egypt, Ethiopia, Afghanistan, Germany, Turkey, India, and Ireland. The hackers' objective extends beyond personal data; they aim to gain access to sensitive company information, such as source code and access credentials, potentially turning an individual's compromised machine into an entry point for a larger organizational breach. This campaign represents a shift in tactics for Mirage Kitten, as they are now developing tools that are compatible with Windows, macOS, and Linux, moving beyond platform-specific exploits.
The attackers leverage LinkedIn's professional profiles to craft highly personalized and convincing job offers, making the phishing attempts more effective than mass-sent messages. The process involves initial contact via LinkedIn, followed by an invitation to a technical assessment. The malicious code is often disguised within seemingly legitimate development test packages, sometimes hosted on cloud services like Amazon Web Services, to appear trustworthy. The attackers also impose time constraints, typically one to three hours, for completing the coding task, and explicitly warn candidates against using AI coding assistants, possibly to prevent detection of the malicious components.
Kaspersky researchers identified two new malware families used in this campaign: NodeRabbit, a remote access trojan that can install fake extensions in Visual Studio Code and alter local code repositories, and PollCat, a JavaScript-based tool that collects system information. These tools are designed to blend in with developers' daily workflows, making detection more difficult. Experts advise job seekers to verify the recruiter's identity and the legitimacy of the job offer independently, exercise caution with any requests to download and run code, and avoid using their work computers for such assessments.