PollCat is a cross-platform remote-access trojan written in obfuscated JavaScript that runs through Node.js on Windows, Linux, and macOS. It is attributed to the Iran-linked cyberespionage actor Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It has been deployed alongside NodeRabbit in recruitment-themed campaigns targeting software developers in financial technology, aviation, and aerospace organizations across the Middle East and Africa.
Operators distribute PollCat through trojanized React coding-assessment archives, using fake recruiter personas on LinkedIn and other employment platforms. The assessment presents an attacker-controlled one-time-password screen and a limited completion window. PollCat starts during application initialization, registers with command-and-control infrastructure, and polls for instructions independently of whether the victim completes authentication.
PollCat supports shell-command execution, arbitrary attacker-supplied JavaScript execution, hidden process execution, process enumeration and termination, file and directory manipulation, drive enumeration, archive operations, and bidirectional file transfers. On Windows, it can execute DLL exports. Its inventory functions collect system, process, and software information and inspect locations associated with security-software vendors. Persistence uses scheduled tasks on Windows, cron entries on Linux, and cron or LaunchAgent mechanisms on macOS.
Its command-and-control protocol includes host registration, command polling, result submission, and file-transfer functions. An unusual registration handshake treats an HTTP 400 response containing a session identifier as successful. Shared handshake behavior, polling structures, command identifiers, and other technical similarities link PollCat to Mirage Kitten's Retrograde/MiniFast backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PollCat arrives through a separate React-based assessment called RankChallenge-react.
A separate React-based challenge, RankChallenge-react, carried PollCat and displayed an attacker-controlled one-time-password screen.
PollCat is a separate cross-platform RAT written in obfuscated JavaScript and distributed through another trojanized coding challenge.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
“The first line of server.js imported a malicious npm package named colorized_terminal... attackers bundled it directly inside the archive's node_modules directory.”
It establishes persistence through ... cron entries on Linux, and cron ... mechanisms on macOS...
NodeRabbit gathers host and network details, lists processes, runs shell commands... PollCat provides ... shell access, and arbitrary JavaScript execution.
PollCat est un RAT multiplateforme écrit en JavaScript obfusqué.
“NodeRabbit can create an extension masquerading as GitHub Copilot Helper,” and actors “incorporated a targeted organization's name into Azure subdomains.”
T1016 — System Network Configuration Discovery (Discovery).
“Implemented functionality includes... process enumeration and termination.”
NodeRabbit gathers host and network details... PollCat provides file transfers, system inventory...
“Implemented functionality includes directory enumeration... [and] drive and volume enumeration.”
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform remote-access trojan that supports file transfer, system inventory, hidden process execution, shell access, and arbitrary JavaScript execution. It persists via Windows scheduled tasks, Linux cron, and macOS cron or LaunchAgent mechanisms, and checks for security-product traces.
Cross-platform remote access trojan delivered through a malicious React-based recruitment assessment. It registers with command-and-control infrastructure and polls for instructions while the application loads, without requiring successful authentication. Capabilities include file transfers, system inventory, hidden process execution, shell access, and arbitrary JavaScript execution. It checks for security products and establishes persistence using scheduled tasks on Windows, cron on Linux, and cron or LaunchAgent mechanisms on macOS.
An obfuscated JavaScript cross-platform remote-access trojan delivered in a trojanized React coding assessment. It registers with C2 and polls for commands independently of the lure's OTP authentication flow. It persists through Windows scheduled tasks, Linux cron, and macOS cron/LaunchAgents, and supports system inventory, file and process operations, command execution, file transfer, archive handling, DLL execution on Windows, hidden execution, and arbitrary JavaScript execution.
A JavaScript/Node.js-based implant disguised as a time-limited React coding assessment. It initiates command-and-control communications when the local application loads, before the victim enters the purported recruiter-provided access code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.