Mirage Kitten Spreads Malware to Aviation and FinTech Companies Across the Middle East and Africa

Mirage Kitten Spreads Malware to Aviation and FinTech Companies Across the Middle East and Africa

Mirage Kitten's expansion into Node.js and JavaScript poses significant risks to the aviation and FinTech sectors.

Bottom line: Mirage Kitten's expansion into Node.js and JavaScript poses significant risks to the aviation and FinTech sectors.

What's happening: Mirage Kitten, a group linked to the Russian SVR intelligence agency, has targeted companies in the Middle East and Africa with a new malware set. The attackers have been using NodeRabbit malware in Node.js, with a CVSS score of 8.5, and PollCat malware in JavaScript, with a CVSS score of 7.5. The malware has been detected in several countries, including Saudi Arabia, Egypt, and South Africa. The attacks began in 2022.

What to do: Security teams should monitor Node.js and JavaScript environments for suspicious activity and implement controls to prevent lateral movement. Kaspersky recommends updating Node.js and JavaScript versions to the latest security patches and using a Web Application Firewall (WAF) to detect and block malware traffic.

Source: Securelist (Kaspersky)