Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2
- Host form
- 0 IP / 38 hostnames
NodeRabbit is a Node.js-based cross-platform remote-access trojan attributed with high confidence to the Iranian-aligned Mirage Kitten group, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore.
Profile source: Mallory opens in a new tabNodeRabbit
NodeRabbit is a Node.js-based cross-platform remote-access trojan attributed with high confidence to the Iranian-aligned Mirage Kitten group, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It targets Windows, Linux, and macOS developer workstations, with confirmed activity against fintech, aviation, and aerospace targets in Afghanistan, Egypt, and Ethiopia. Operators distribute it through recruiter impersonation and recruitment-themed spearphishing on LinkedIn and job-search platforms, using trojanized coding-challenge projects that contain bundled malicious npm packages. NodeRabbit provides host, network, process, filesystem, and drive reconnaissance; executes shell commands and attacker-provided Node.js code; and can create, modify, delete, and collect files. Variants use encrypted web-based command-and-control, support proxy-aware communications, and include anti-analysis checks. Persistence is platform-specific and includes Windows autorun or scheduled-task mechanisms, Linux cron, and macOS LaunchAgents. One variant adds local Outlook artifact collection, fake Visual Studio Code extension persistence, and Git-hook injection, enabling continued access through developer workflows.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
NodeRabbit est un RAT multiplateforme (Windows, Linux, macOS) écrit en Node.js. Trois variantes ont été identifiées.
NodeRabbit is a remote-access trojan capable of infecting Windows, Linux and macOS systems. Once installed, it allows attackers to collect information about the victim and their computer, create or modify files and execute additional commands.
NodeRabbit is a remote-access trojan capable of infecting Windows, Linux and macOS systems. Once installed, it allows attackers to collect information about the victim and their computer, create or modify files and execute additional commands.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.