Mirage Kitten Toolset Expansion: Reverse SSH Tunnelling, TWOSTROKE, NodeRabbit and PollCat
Source report →Two vendor reports published a week apart in late August and early September 2026 cover the same Iranian nexus actor. Group-IB tracks it as Tortoiseshell and Kaspersky as Mirage Kitten; it is also tracked as UNC1549 and Nimbus Manticore, and is affiliated with the Islamic Revolutionary Guard Corps. The group has been active since at least 2018 against defence, aerospace, information technology service providers and military organisations, and the newer reporting adds confirmed victims in financial technology and in aviation across the Middle East and Africa. Its established methods include supply chain compromise, watering hole attacks and recruiter personas on professional networks.
Group-IB identified two previously unreported native components, both Windows libraries named after a genuine system library and both passing every call on to the real one so the program that loads them keeps working normally. The first opens a reverse tunnel: it drives the operating system's own secure shell client out to an operator controlled server on a web port, disables the checks that would otherwise prompt, and asks that server to forward a port back down the connection, giving the operator a route into the network from their own machine. The second is a new build of the TWOSTROKE backdoor, which reports to the first of three hardcoded servers that answers and takes commands to move files, run programs, enumerate the host and delete traces.
Kaspersky documented a newer direction, the group's first implants written in Node.js and JavaScript, named NodeRabbit and PollCat. Both run on Windows, Linux and macOS from a single codebase, and both arrive as trojanized coding challenge archives sent by fake recruiter accounts on job search platforms, hosted on cloud storage and pressed on the target under a short deadline. The archives carry a tampered dependency bundled into the project rather than published publicly, so running the exercise is enough to start the implant in the background. Later variants check whether they are being analysed and exit if they are, and route their traffic through whatever corporate proxy they find.
Persistence in both implants hides behind vendor names. Each copies itself into an application data folder named for a browser updater, a driver support assistant or a networking component, places a copy of the interpreter beside it, and points an autostart entry or a daily task at the pair. The newest variant also works through developer habits, installing a fake editor extension presented as a coding assistant and adding a launcher to a repository's version control hooks so a later routine branch switch starts it again. That variant collects mail account addresses and looks for installed security products.
The infrastructure differs between the two toolsets. The native tooling sits behind a pool of twenty seven rented relay servers reached through short country named subdomains across two registered domains, one active and one suspended by its registrar, and the servers did not move when the suspended name was withdrawn. The Node implants instead use cloud application hosting and domains behind a large content delivery network, in some cases building the target organisation's own name into the address so the traffic reads as that organisation's own service.
IOCs (156)
Scan your environment for IOCs →SHA256 FILE HASH 2
d23c1b7b917f53e4e5a608e9870e574f7461eead277726249c4acf4a2b0bef4b597c40e0b23f38f30a3c85be0510b14985b2948895819c899e3f3c8f200aa437SHA1 FILE HASH 2
e39bb97415978fa3484298735bd020662a51f3abc0dba95939f7fc1a55b7aa6c132a204f073a981dMD5 FILE HASH 14
07dd28b748656e9e1a870c538d6df68cdb58adc4a6c192520ed509b20a928279cbaaf0900a13f28e380f49adecec932c1ea83e4e4592b01e4acab63eb867bee5366515822d5ac1cc500711ef57a2e32ecf449f1992c2819e62ac44a0b06ac2e7e95a4366686e3f786ea3c056fab5b0dade5af16a3757ef700b01dc34d67079aebe086789568441d0d7e4679aee51f566e259c5edf158aac4cfe14f77ddd0b196291ac3abe73c5158e59a437b75d5f0aa0962f56d7ec69f4f2a0162dcbe22116b795e053a990a1569ffdcb57f48f6d085810f8e3b88eb05f710c09552941d6f56DOMAIN 96
neexportfolio[.]comneexportfolio.azurewebsites[.]netneexportfolio.eastus.cloudapp.azure[.]comlocat[.]sbstiktok-u[.]sbsaecert[.]orgau1.locat[.]sbsjp2.locat[.]sbsuk1.locat[.]sbsuk2.locat[.]sbsbel1.locat[.]sbscan2.locat[.]sbssau1.locat[.]sbssau2.locat[.]sbssau3.locat[.]sbsuae1.locat[.]sbsuae2.locat[.]sbsuae3.locat[.]sbsuae4.locat[.]sbsuae5.locat[.]sbsuae6.locat[.]sbsuae7.locat[.]sbsuae8.locat[.]sbsuae9.locat[.]sbs5orka.locat[.]sbscloud.locat[.]sbsuae10.locat[.]sbsuae11.locat[.]sbsuae12.locat[.]sbsuae13.locat[.]sbsuae14.locat[.]sbsbridge1.locat[.]sbsau1.tiktok-u[.]sbsjp2.tiktok-u[.]sbsuk1.tiktok-u[.]sbsuk2.tiktok-u[.]sbsbel1.tiktok-u[.]sbscan2.tiktok-u[.]sbssau1.tiktok-u[.]sbssau2.tiktok-u[.]sbssau3.tiktok-u[.]sbsuae1.tiktok-u[.]sbsuae2.tiktok-u[.]sbsuae3.tiktok-u[.]sbsuae4.tiktok-u[.]sbsuae5.tiktok-u[.]sbsuae6.tiktok-u[.]sbsuae7.tiktok-u[.]sbsuae8.tiktok-u[.]sbsuae9.tiktok-u[.]sbs5orka.tiktok-u[.]sbscloud.tiktok-u[.]sbsuae10.tiktok-u[.]sbsuae11.tiktok-u[.]sbsuae12.tiktok-u[.]sbsuae13.tiktok-u[.]sbsuae14.tiktok-u[.]sbsbridge1.tiktok-u[.]sbsoracle-challenge.s3.us-east-1.amazonaws[.]comnaturalapplication.azurewebsites[.]netretaildemo.azurewebsites[.]nettubitak.azurewebsites[.]netrgbteller.azurewebsites[.]netwslwebui.azurewebsites[.]netplugplay.azurewebsites[.]netcrossdwm.azurewebsites[.]netwdisystem.azurewebsites[.]netwslmenus.azurewebsites[.]netdnshnsdev.azurewebsites[.]nethpjumpsrv.azurewebsites[.]netstorview.azurewebsites[.]netkyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]netgreenyjsgfd.azurewebsites[.]nethelptellerbls.azurewebsites[.]nettimedrv.azurewebsites[.]netuserwellgtfs.azurewebsites[.]nethecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]nethealthcomfsdpower[.]comvisitfinancedentists[.]commsmanagementgrp[.]commsmanagementgrpmedia[.]comlifespotify[.]comgamebarapp.azurewebsites[.]netgamebarappinformation.azurewebsites[.]netsahi-finance[.]comhealthful-hub[.]comneumedicahealthcare[.]comoptimumhealthcredit[.]comhealthfullyrecipes[.]comrefreshhealthandwellness[.]comhealthvitalitycare[.]comaceofspadesmanagement[.]comglmediaagency[.]comdigimediaskill[.]comhealthyweightplan[.]commens-health-online[.]comIP ADDRESS 27
72.56.34[.]5279.141.167[.]23085.208.86[.]14089.44.80[.]689.44.80[.]4289.44.80[.]5689.44.80[.]6189.44.80[.]8689.44.80[.]9689.44.80[.]16889.44.80[.]23491.193.16[.]18794.126.227[.]2094.126.227[.]11995.85.235[.]995.174.68[.]199139.84.202[.]187167.179.89[.]68172.86.98[.]113185.66.68[.]213185.253.116[.]71185.253.116[.]81185.253.116[.]99185.253.116[.]166185.253.116[.]242185.253.118[.]246188.119.149[.]200URL 2
https://oracle-challenge.s3[.]us-east-1.amazonaws[.]com/Front-Technical-Challenge.ziphttps://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validateFILE NAME 13
msedge_update.jsidriver_support.jsFrontEnd-Task.zipFront-Technical-Challenge.zipTask-FullStack.zipfullstack-1536.zipwebapp76592.zipwebapp76531.zipchallenges-17831.zipchallenges-17832.zipProject-1802.zipCase-34234.zipRankChallenge-react-6uJSX3-main.zipDetections (10)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- OpenSSH Private Key Staged in the Local System Profile Directory
- Run Key Value Pointing to a Script in an Application Data Path
- Mirage Kitten Node Implant Persistence Artifact Written to a Vendor Named Path
- Mirage Kitten Node Implant Scheduled Task Registered
- Git Hook Written by a Node Interpreter
- Renamed Node Interpreter Executed
- Outbound Web Request Matching NodeRabbit or PollCat Command and Control URI Paths
- Known Sideloading Target Library Loaded From a User Writable Directory
- New Destination Port for a Shell or Script Interpreter