Fintech Developers, Others, Targeted by Iranian Hackers

Tokoni
Tokoni Uti
Dr. Tokoni Uti is an experienced writer and researcher specializing in fintech, digital banking, Global finance, and technology. With a PhD in Communication and Marketing, she...
3 Min Read

Last Updated on September 2, 2026 by TMB

Fintech, aerospace, and aviation developers have found themselves the target of an Iranian hacking group looking to spread malware. A recent report by cybersecurity firm Kaspersky identified the group of hackers as Mirage Kitten.

The report highlights that developers in Egypt, Ethiopia, and Afghanistan have been especially targeted, usually via fraudulent job opportunities. Typically, we see malware attacks as going after centralized systems and through phishing schemes targeted at everyday consumers. But this new scheme reveals a sophisticated network trying to embed new and malicious software across the globe.

How Mirage Kitten Operates

As per Kaspersky, the scheme typically starts with job ads on sites like LinkedIn, even impersonating high-profile tech companies. As part of the ‘recruitment’ process, victims were asked to complete a technical assignment that included downloading certain software.

Often, they were told to review an application and identify flaws. In classic scammer fashion, they were given a strict 3-hour time limit to complete the task. Less common is the fact that victims were told they could not use any AI assistance. Kaspersky suggests that AI might have flagged the software as malware and the job as a scam.

Hackers

The software, dubbed NodeRabbit and PollCat, was identified as malicious programs that, once installed, gave the criminals access to victims’ sensitive information. NodeRabbit, for example, can infect Windows, Linux, and macOS systems and execute remote commands. Rather than getting a job, these developers unwittingly give hackers remote control over their devices.

Scammers even went a step further to conceal their crimes by using Microsoft Azure and Cloudflare infrastructure to disguise themselves as legitimate organizations. The current targets are concentrated in Africa and the Middle East.

The Wider Implications

Beyond the impact on these individuals, there is a broader systemic issue to address. These hackers are likely targeting fintech professionals not only for their own personal information but also for company details. A fintech professional who applies for a new job whilst still working their old one, or has certain information on their devices, could unwittingly expose their employers and customers to these malicious actors.

Companies around the world have taken steps to educate and protect their employees against phishing schemes (to varying results) , but now tactics have evolved and become more complex. While the advice to never download any software you are unsure of holds true, the use of AI in job recruitment is a bit of a grey area. 

Some legitimate organizations actually ban the use of AI, while others allow it. Now, in light of this issue, we can expect some system-wide changes or new guidance for companies and developers.

Share This Article