Fake coding tests target aviation and fintech specialists

Published September 7, 2026

Kaspersky says an Iran-linked espionage group used fake recruitment tests to deliver NodeRabbit and PollCat malware. Researchers found variants on systems in Afghanistan, Egypt and Ethiopia.

Report priority
Medium

How it works

  • A fake recruiter contacts a technology specialist through LinkedIn or another job platform and asks them to download and run a coding assignment.
  • The attacker controls the project, and a hidden malicious component starts when the target runs it.
  • Kaspersky says NodeRabbit can collect system information, change files and execute commands on Windows, Linux and macOS.
  • PollCat is reported to maintain access and deliver more malicious files.

What to do

First, review recent recruiter conversations and downloaded coding assignments. Relevant warning signs include a cloud-hosted archive, a one-hour or three-hour deadline, instructions not to use AI assistants, or a short-lived six-digit access code. These signs don't prove infection. If you ran such a project, send the recruiter profile, download URL, archive, execution time and device details to your IT or security team and ask whether they found NodeRabbit, PollCat or related activity on the device or network.

Don't run an unverified coding project, and confirm the recruiter through the employer's official hiring channel. If you already ran one, contact your organization's IT or security team and refer them to the reported campaign details. Deleting the project or updating software wouldn't by itself confirm that any installed malware was removed.

Technical details

A fake recruiter messages a developer on LinkedIn with a job offer at a well known tech company and sends a ZIP file hosted on Amazon S3 containing a timed coding test. The developer opens the project and starts fixing the frontend bugs it describes, unaware that a backend file quietly imports a trojanized package called colorized_terminal. That package launches the NodeRabbit malware in the background, which fingerprints the machine and hides itself as a Windows Edge update process or a macOS launch agent so it keeps running after reboot.

Kaspersky attributes the campaign to Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm and Nimbus Manticore. NodeRabbit lets attackers remotely control Windows, Linux and macOS systems. PollCat is described as malware that maintains access and can deliver additional files.