AI generated
Cybersecurity researchers have uncovered an espionage campaign targeting software developers and specialists in aviation.

Cyber-espionage campaign targets developers in Egypt with fake job offers, researchers say

Mohammad El-Taher
Published Wednesday, September 2, 2026 - 16:48

Cybersecurity researchers have uncovered an espionage campaign targeting software developers and specialists in the aviation, aerospace and FinTech sectors, using fake job offers to trick victims into running coding projects that contain malicious tools granting attackers remote access to their devices.

Kaspersky identified victims of the campaign in Egypt, Ethiopia and Afghanistan, though that doesn’t mean all three sectors were targeted in every country.

According to the cybersecurity and technology news site The Record, the campaign is linked to the espionage group Mirage Kitten, also known to other security firms as UNC1549, Smoke Sandstorm and Nimbus Manticore, amid suspicions of Iranian involvement in the operations.

During the investigation, Kaspersky researchers discovered two new malware families, which they named NodeRabbit and PollCat — both remote access tools that let an attacker execute commands on an infected device and access its files and data.

A booby-trapped hiring test

The campaign begins with fake recruiter accounts that contact victims through job search platforms, offering them what appear to be genuine job opportunities.

In one case, an attacker posed as a recruiter at a major technology company and contacted a software engineer about a job opportunity, then asked him to complete a technical test.

The attacker sent a link to download a coding project hosted on Amazon S3, and the engineer was asked to review the project’s interface and fix its bugs within three hours. But one of the files he wasn’t asked to modify contained the malicious component.

The test instructions also barred the use of AI coding assistants — a restriction researchers believe was meant to reduce the chances of the suspicious code being spotted.

Once the project is run, the malware begins operating in the background alongside the application visible to the victim.

Kaspersky discovered the first version of NodeRabbit on a device in Afghanistan, then found two more advanced versions — one in Egypt, the other in Ethiopia.

The malware runs on Windows, Linux and macOS, and can gather information about the device and running processes, execute remote commands, read, write and delete files, and collect data on network configurations.

The version found in Egypt stood out for its ability to detect certain security analysis environments and shut itself down before connecting to the attackers' servers; it can also partially handle proxy settings within corporate networks.

The version found in Ethiopia, meanwhile, had added persistence mechanisms for staying on developers’ machines, including creating a fake Visual Studio Code extension named “GitHub Copilot Helper,” and modifying files within Git repositories so the malware relaunches alongside routine operations on the project.

Targeting developers holds particular value for attackers, since developers at many organisations hold elevated access to internal systems and technical resources — making their infected devices a potential foothold for reaching other parts of an organisation's network.

The campaign also made use of the PollCat malware, hidden inside a test to fix a React-based application.

Applicants are presented with a one-hour test and asked to enter a six-digit code sent by the fake recruiter, who tells them the code is valid for only a short time — an apparent attempt to push them into running the project quickly.

But researchers found that entering the code isn't actually necessary to trigger the infection: PollCat begins operating and connecting to attacker-controlled infrastructure as soon as the application is run.

Once installed, the malware can execute remote commands, transfer files, and gather information about the system, installed software and running processes, in addition to searching folders that include Documents and some Outlook data.

A possible Iran connection

Cybersecurity firms link Mirage Kitten’s activity to Iran, though with varying degrees of confidence.

Google’s Mandiant said in earlier research that it links the group known as UNC1549 to Iran with medium confidence, pointing to overlap between its activity and that of Tortoiseshell, a group previously linked publicly to Iran’s Islamic Revolutionary Guard Corps.

Kaspersky, for its part, attributes the new campaign to Mirage Kitten with high confidence, based on similarities in the malware and infrastructure used, targeting patterns, and methods of communicating with attacker-controlled servers.

The campaign comes weeks after Kaspersky disclosed another piece of malware it named NightLedger, which it said was linked to the same group. Researchers at the time identified victims in Egypt, alongside government bodies and companies in Jordan and Tanzania, aviation-sector institutions in Pakistan, telecom companies in Ethiopia, and financial-sector entities in Burkina Faso.

Mandiant has also documented UNC1549′s use of fake job opportunities and recruitment sites since 2024 to target workers in the technology, defense and aviation sectors across the Middle East, suggesting that exploiting recruitment processes is a recurring tactic in the group’s activity.