Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Iranian group Nimbus Manticore deploys two newly documented cross-platform RATs via fake coding tests, extending developer-targeted social engineering to Linux and macOS—a direct risk for engineering-heavy European firms.
Summary written by editorial AI · Source link below
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.
Russian cybersecurity company Kaspersky is tracking the
Editorial Analysis
Developer-targeted social engineering via recruitment pipelines is an increasingly common initial access vector; cross-platform RAT capability means Linux and macOS developer workstations are no longer safe assumptions.
Enforce sandboxed execution environments for any external coding assessments and verify endpoint protection covers Linux and macOS developer machines.
Iranian state hackers are weaponising fake job coding tests to deploy cross-platform malware targeting software developers.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d