Skip to content

NodeRabbit

NodeRabbit is a cross-platform Node.js remote-access trojan attributed with high confidence to the Iran-linked cyberespionage group Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore.

Profile source: Mallory opens in a new tab

NodeRabbit

Family profile

NodeRabbit is a cross-platform Node.js remote-access trojan attributed with high confidence to the Iran-linked cyberespionage group Mirage Kitten, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It targets Windows, Linux, and macOS developer workstations. The malware has been distributed through recruitment-themed spearphishing campaigns in which fake recruiter personas send software engineers trojanized coding assessments containing locally bundled malicious npm dependencies. Confirmed targeting includes fintech, aviation, and aerospace organizations in Afghanistan, Egypt, and Ethiopia.

NodeRabbit runs as a background process and uses AES-256-GCM-protected web communications for command-and-control. Its capabilities include host, network, process, directory, mounted-volume, and development-project discovery; arbitrary shell-command and supplied Node.js-script execution; file creation, modification, deletion, and retrieval; process management; and configurable beaconing. Later variants add enterprise proxy discovery and authenticated proxy tunneling, anti-analysis checks based on host resources, uptime, names, and analysis tools, and Outlook artifact discovery for local account-address collection. When analysis conditions are detected, it can terminate without contacting its command server.

NodeRabbit implements platform-specific persistence, including Windows autorun mechanisms or scheduled tasks, Linux cron, and macOS LaunchAgents. Advanced variants can install a counterfeit Visual Studio Code extension, attempt to disable Visual Studio Code Workspace Trust, and inject launchers into Git hooks so the implant is restarted during routine source-control operations. These features indicate a focus on durable access to software-development environments for espionage.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

3 named in public reporting
Smoke Sandstorm

NodeRabbit is a cross-platform RAT developed using Node.js... More advanced variants introduce anti-analysis checks, corporate proxy support, expanded C2 capabilities, Outlook account discovery, and persistence through malicious Visual Studio Code extensions and Git hooks.

Mirage Kitten

NodeRabbit is a cross-platform RAT developed using Node.js... More advanced variants introduce anti-analysis checks, corporate proxy support, expanded C2 capabilities, Outlook account discovery, and persistence through malicious Visual Studio Code extensions and Git hooks.

Nimbus Manticore

NodeRabbit is a cross-platform RAT developed using Node.js... More advanced variants introduce anti-analysis checks, corporate proxy support, expanded C2 capabilities, Outlook account discovery, and persistence through malicious Visual Studio Code extensions and Git hooks.

MITRE ATT&CK

NodeRabbit in ATT&CK

42 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.