Skip to content

NodeRabbit

NodeRabbit is a Node.js-based cross-platform remote-access trojan attributed with high confidence to the Iranian-aligned Mirage Kitten group, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore.

Profile source: Mallory opens in a new tab

NodeRabbit

Family profile

NodeRabbit is a Node.js-based cross-platform remote-access trojan attributed with high confidence to the Iranian-aligned Mirage Kitten group, also tracked as UNC1549, Smoke Sandstorm, and Nimbus Manticore. It targets Windows, Linux, and macOS developer workstations, with confirmed activity against fintech, aviation, and aerospace targets in Afghanistan, Egypt, and Ethiopia. Operators distribute it through recruiter impersonation and recruitment-themed spearphishing on LinkedIn and job-search platforms, using trojanized coding-challenge projects that contain bundled malicious npm packages. NodeRabbit provides host, network, process, filesystem, and drive reconnaissance; executes shell commands and attacker-provided Node.js code; and can create, modify, delete, and collect files. Variants use encrypted web-based command-and-control, support proxy-aware communications, and include anti-analysis checks. Persistence is platform-specific and includes Windows autorun or scheduled-task mechanisms, Linux cron, and macOS LaunchAgents. One variant adds local Outlook artifact collection, fake Visual Studio Code extension persistence, and Git-hook injection, enabling continued access through developer workflows.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 2, 2026
Feed role
C2
Host form
0 IP / 38 hostnames

Leading locations

  • US16
  • NL6
  • IE1

Leading providers

  • Cloudflare, Inc.15
  • Microsoft Corporation7
  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 23
  • Anycast 15

Reported operators

Threat actors

3 named in public reporting
Mirage Kitten

NodeRabbit est un RAT multiplateforme (Windows, Linux, macOS) écrit en Node.js. Trois variantes ont été identifiées.

Smoke Sandstorm

NodeRabbit is a remote-access trojan capable of infecting Windows, Linux and macOS systems. Once installed, it allows attackers to collect information about the victim and their computer, create or modify files and execute additional commands.

Nimbus Manticore

NodeRabbit is a remote-access trojan capable of infecting Windows, Linux and macOS systems. Once installed, it allows attackers to collect information about the victim and their computer, create or modify files and execute additional commands.

MITRE ATT&CK

NodeRabbit in ATT&CK

39 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.