Hackers use fake recruiter profiles and coding tests on LinkedIn to trick developers into installing stealthy cross platform malware.
Cybersecurity researchers have uncovered a dangerous hacker campaign that uses fake recruitment offers on LinkedIn to infect software developers with new computer viruses.
Hackers create highly believable fake recruiter profiles on professional networking sites and message job seeking engineers with exciting job openings.
To start the hiring process, the fake recruiters ask candidates to download a coding file and complete a technical test within a short time limit.
However, as soon as the programmer opens and runs the test project on their laptop, hidden malicious software installs itself in the background.
The secret virus gives hackers total remote access to the developer’s computer, allowing them to steal confidential company files, personal passwords, and internal business accounts without raising suspicion.
The cybersecurity alert was publicly released by research teams at PolySwarm and published by security analysts on Wednesday, September 9, 2026.
Investigators traced the attack campaign back to a state linked foreign hacking unit known as Mirage Kitten, which is also tracked as group UNC1549.
The cybercriminals targeted software engineers working inside high value industries, including aviation companies, aerospace manufacturers, and financial technology platforms operating across nations like Egypt, Ethiopia, and Afghanistan.
By deploying versatile new software tools named NodeRabbit and PollCat, the attackers successfully infected computers running Windows, Apple Mac, and Linux operating systems simultaneously.
The main reason cybercriminals are using fake recruitment offers to target software developers is that programmers frequently download, inspect, and run unknown computer code as part of normal job interviews.
To make the trick work, hackers place tight time limits on the test and tell candidates not to use automated smart tools, creating artificial stress that stops job seekers from carefully checking hidden project files.
Because software engineers hold broad access keys to private corporate software, compromising a single developer’s computer gives hackers an easy backdoor entrance into entire corporate networks, cloud storage systems, and private email records.
Explaining how bad actors trick job candidates into launching hidden computer viruses during routine job tests, security researchers at PolySwarm noted that “the campaign uses recruiter personas on LinkedIn and other employment platforms to deliver projects that appear safe enough to run”.
Detailing why infecting developer workstations creates severe security risks for major technology companies, threat analysts warned that “a successful compromise can give an intruder a foothold on a machine holding source code, internal repositories, credentials, and access to corporate services”.
Highlighting how hackers switched programming languages to build tools capable of hitting all major computer systems at once, cybersecurity expert Omar Amin stated that “the shift from traditional compiled malware to JavaScript-based threats marks a change in the Mirage Kitten tactics”.
By exposing fake recruiter traps on job platforms, security experts are urging workers to verify employment messages through official company channels before running downloaded files.
Checking project files carefully ensures that job seekers stay safe from sneaky online scams while hunting for new career opportunities.

