PolySwarm analysts provided information on Mirage Kitten's cyberespionage campaign targeting software engineers through fake recruiter personas and trojanized coding challenges, delivering NodeRabbit and PollCat cross-platform RATs, and IOCs of PolySwarm samples.
Public source
Publisher name
Public post
Mirage Kitten conducted a cyberespionage campaign targeting software engineers through fake recruiter personas and trojanized coding challenges. The campaign delivers tw…
Company
PolySwarm
Crowdsourced threat detection
- Industry
- Computer and Network Security
- Location
- San Diego, US
- Company size
- 11–50 employees
About PolySwarm
PolySwarm is a crowdsourced threat intelligence marketplace that provides a more effective way to detect, analyze and respond to the latest threats, the ones more likely to go undetected by existing solutions. We are a launchpad for new technologies and innovative threat detection methods, where commercial solutions and specialized engines compete to detect threats and get compensated based on performance PolySwarm facilitates marketplace transactions with an Ethereum erc20 token (NCT). PolySwarm uses NCT in their community, and network for detecting malware. NCT rewards are distributed to users who provide relevant cybersecurity data while NCT is used to access insights provided by the network. For more information, please visit polyswarm.io or try PolySwarm free at polyswarm.network.
See moreLatest activity
Latest activity from PolySwarm
4 signals
Research & Knowledge
PolySwarm reported on Russian state-sponsored threat group BlueDelta deploying the HOOKEDGE Windows backdoor in espionage campaigns targeting European diplomatic, government, and defense-related organizations.
Presence & Recognition
PolySwarm attended the Falcon 2026 cybersecurity conference in Las Vegas.
Research & Knowledge
PolySwarm published a blog post detailing the SLEEPWALKER novel passive Windows backdoor malware designed for DLL side-loading into the ESET Management Agent process ERAAgent.exe and not autonomously beaconing or containing fixed C2 infrastructure.
Discover more
Similar signals
Similar public activity from other companies.
Research & Knowledge
The DFIR Report
The DFIR Report published a nine-day espionage operation involving a fake-CAPTCHA (ClickFix) lure, RomComRAT implants, lateral movement, credential harvesting, and a massive data-theft campaign ending in domain compromise for the private case 35646.
Research & Knowledge
Picus Security
Picus Security published an analysis breaking down the full chain of the CrashFix ModeloRAT campaign, including poisoned search ads, RC4-encrypted C2 traffic, and eight commands giving operators full remote control.
Research & Knowledge
Proofpoint
Proofpoint published observations of a new RAT and C2 framework called PackClient used by Chinese-speaking TA4922 on Hacker News
Research & Knowledge
VMRay
VMRay published an analysis by H. Fatih Akaron in the Cyber Threat Alliance's September newsletter discussing malware behavior as a transferable threat intelligence signal.
Research & Knowledge
ThreatLight