← All briefs
high September 17, 2026

Mirage Kitten Toolset Expansion: Reverse SSH Tunnelling, TWOSTROKE, NodeRabbit and PollCat

Source report →

Two vendor reports published a week apart in late August and early September 2026 cover the same Iranian nexus actor. Group-IB tracks it as Tortoiseshell and Kaspersky as Mirage Kitten; it is also tracked as UNC1549 and Nimbus Manticore, and is affiliated with the Islamic Revolutionary Guard Corps. The group has been active since at least 2018 against defence, aerospace, information technology service providers and military organisations, and the newer reporting adds confirmed victims in financial technology and in aviation across the Middle East and Africa. Its established methods include supply chain compromise, watering hole attacks and recruiter personas on professional networks.

Group-IB identified two previously unreported native components, both Windows libraries named after a genuine system library and both passing every call on to the real one so the program that loads them keeps working normally. The first opens a reverse tunnel: it drives the operating system's own secure shell client out to an operator controlled server on a web port, disables the checks that would otherwise prompt, and asks that server to forward a port back down the connection, giving the operator a route into the network from their own machine. The second is a new build of the TWOSTROKE backdoor, which reports to the first of three hardcoded servers that answers and takes commands to move files, run programs, enumerate the host and delete traces.

Kaspersky documented a newer direction, the group's first implants written in Node.js and JavaScript, named NodeRabbit and PollCat. Both run on Windows, Linux and macOS from a single codebase, and both arrive as trojanized coding challenge archives sent by fake recruiter accounts on job search platforms, hosted on cloud storage and pressed on the target under a short deadline. The archives carry a tampered dependency bundled into the project rather than published publicly, so running the exercise is enough to start the implant in the background. Later variants check whether they are being analysed and exit if they are, and route their traffic through whatever corporate proxy they find.

Persistence in both implants hides behind vendor names. Each copies itself into an application data folder named for a browser updater, a driver support assistant or a networking component, places a copy of the interpreter beside it, and points an autostart entry or a daily task at the pair. The newest variant also works through developer habits, installing a fake editor extension presented as a coding assistant and adding a launcher to a repository's version control hooks so a later routine branch switch starts it again. That variant collects mail account addresses and looks for installed security products.

The infrastructure differs between the two toolsets. The native tooling sits behind a pool of twenty seven rented relay servers reached through short country named subdomains across two registered domains, one active and one suspended by its registrar, and the servers did not move when the suspended name was withdrawn. The Node implants instead use cloud application hosting and domains behind a large content delivery network, in some cases building the target organisation's own name into the address so the traffic reads as that organisation's own service.

SHA256 FILE HASH 2
d23c1b7b917f53e4e5a608e9870e574f7461eead277726249c4acf4a2b0bef4b
597c40e0b23f38f30a3c85be0510b14985b2948895819c899e3f3c8f200aa437
SHA1 FILE HASH 2
e39bb97415978fa3484298735bd020662a51f3ab
c0dba95939f7fc1a55b7aa6c132a204f073a981d
MD5 FILE HASH 14
07dd28b748656e9e1a870c538d6df68c
db58adc4a6c192520ed509b20a928279
cbaaf0900a13f28e380f49adecec932c
1ea83e4e4592b01e4acab63eb867bee5
366515822d5ac1cc500711ef57a2e32e
cf449f1992c2819e62ac44a0b06ac2e7
e95a4366686e3f786ea3c056fab5b0da
de5af16a3757ef700b01dc34d67079ae
be086789568441d0d7e4679aee51f566
e259c5edf158aac4cfe14f77ddd0b196
291ac3abe73c5158e59a437b75d5f0aa
0962f56d7ec69f4f2a0162dcbe22116b
795e053a990a1569ffdcb57f48f6d085
810f8e3b88eb05f710c09552941d6f56
DOMAIN 96
neexportfolio[.]com
neexportfolio.azurewebsites[.]net
neexportfolio.eastus.cloudapp.azure[.]com
locat[.]sbs
tiktok-u[.]sbs
aecert[.]org
au1.locat[.]sbs
jp2.locat[.]sbs
uk1.locat[.]sbs
uk2.locat[.]sbs
bel1.locat[.]sbs
can2.locat[.]sbs
sau1.locat[.]sbs
sau2.locat[.]sbs
sau3.locat[.]sbs
uae1.locat[.]sbs
uae2.locat[.]sbs
uae3.locat[.]sbs
uae4.locat[.]sbs
uae5.locat[.]sbs
uae6.locat[.]sbs
uae7.locat[.]sbs
uae8.locat[.]sbs
uae9.locat[.]sbs
5orka.locat[.]sbs
cloud.locat[.]sbs
uae10.locat[.]sbs
uae11.locat[.]sbs
uae12.locat[.]sbs
uae13.locat[.]sbs
uae14.locat[.]sbs
bridge1.locat[.]sbs
au1.tiktok-u[.]sbs
jp2.tiktok-u[.]sbs
uk1.tiktok-u[.]sbs
uk2.tiktok-u[.]sbs
bel1.tiktok-u[.]sbs
can2.tiktok-u[.]sbs
sau1.tiktok-u[.]sbs
sau2.tiktok-u[.]sbs
sau3.tiktok-u[.]sbs
uae1.tiktok-u[.]sbs
uae2.tiktok-u[.]sbs
uae3.tiktok-u[.]sbs
uae4.tiktok-u[.]sbs
uae5.tiktok-u[.]sbs
uae6.tiktok-u[.]sbs
uae7.tiktok-u[.]sbs
uae8.tiktok-u[.]sbs
uae9.tiktok-u[.]sbs
5orka.tiktok-u[.]sbs
cloud.tiktok-u[.]sbs
uae10.tiktok-u[.]sbs
uae11.tiktok-u[.]sbs
uae12.tiktok-u[.]sbs
uae13.tiktok-u[.]sbs
uae14.tiktok-u[.]sbs
bridge1.tiktok-u[.]sbs
oracle-challenge.s3.us-east-1.amazonaws[.]com
naturalapplication.azurewebsites[.]net
retaildemo.azurewebsites[.]net
tubitak.azurewebsites[.]net
rgbteller.azurewebsites[.]net
wslwebui.azurewebsites[.]net
plugplay.azurewebsites[.]net
crossdwm.azurewebsites[.]net
wdisystem.azurewebsites[.]net
wslmenus.azurewebsites[.]net
dnshnsdev.azurewebsites[.]net
hpjumpsrv.azurewebsites[.]net
storview.azurewebsites[.]net
kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net
greenyjsgfd.azurewebsites[.]net
helptellerbls.azurewebsites[.]net
timedrv.azurewebsites[.]net
userwellgtfs.azurewebsites[.]net
hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net
healthcomfsdpower[.]com
visitfinancedentists[.]com
msmanagementgrp[.]com
msmanagementgrpmedia[.]com
lifespotify[.]com
gamebarapp.azurewebsites[.]net
gamebarappinformation.azurewebsites[.]net
sahi-finance[.]com
healthful-hub[.]com
neumedicahealthcare[.]com
optimumhealthcredit[.]com
healthfullyrecipes[.]com
refreshhealthandwellness[.]com
healthvitalitycare[.]com
aceofspadesmanagement[.]com
glmediaagency[.]com
digimediaskill[.]com
healthyweightplan[.]com
mens-health-online[.]com
IP ADDRESS 27
72.56.34[.]52
79.141.167[.]230
85.208.86[.]140
89.44.80[.]6
89.44.80[.]42
89.44.80[.]56
89.44.80[.]61
89.44.80[.]86
89.44.80[.]96
89.44.80[.]168
89.44.80[.]234
91.193.16[.]187
94.126.227[.]20
94.126.227[.]119
95.85.235[.]9
95.174.68[.]199
139.84.202[.]187
167.179.89[.]68
172.86.98[.]113
185.66.68[.]213
185.253.116[.]71
185.253.116[.]81
185.253.116[.]99
185.253.116[.]166
185.253.116[.]242
185.253.118[.]246
188.119.149[.]200
URL 2
https://oracle-challenge.s3[.]us-east-1.amazonaws[.]com/Front-Technical-Challenge.zip
https://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate
FILE NAME 13
msedge_update.js
idriver_support.js
FrontEnd-Task.zip
Front-Technical-Challenge.zip
Task-FullStack.zip
fullstack-1536.zip
webapp76592.zip
webapp76531.zip
challenges-17831.zip
challenges-17832.zip
Project-1802.zip
Case-34234.zip
RankChallenge-react-6uJSX3-main.zip

Detections (10)

Enable detections →

Connect your environment for suggestions and queries personalized to your security telemetry.

  • OpenSSH Private Key Staged in the Local System Profile Directory
  • Run Key Value Pointing to a Script in an Application Data Path
  • Mirage Kitten Node Implant Persistence Artifact Written to a Vendor Named Path
  • Mirage Kitten Node Implant Scheduled Task Registered
  • Git Hook Written by a Node Interpreter
  • Renamed Node Interpreter Executed
  • Outbound Web Request Matching NodeRabbit or PollCat Command and Control URI Paths
  • Known Sideloading Target Library Loaded From a User Writable Directory
  • New Destination Port for a Shell or Script Interpreter