<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests]]></title><description><![CDATA[<p dir="auto">A newly attributed campaign from the Iranian threat actor tracked as Nimbus Manticore reveals a notable expansion in its operational scope, moving beyond its traditional Windows-focused arsenal to target Linux and Apple macOS environments. The group is now leveraging two previously undocumented malware families, both built on Node.js and JavaScript, to deliver cross-platform remote access trojans (RATs) that mark a significant evolution in their technical capabilities.</p>
<p dir="auto">Kaspersky researchers, who are tracking the activity, observed the group employing a social engineering lure centered on fake job recruitment. The attackers pose as potential employers and send coding test challenges to targets, a tactic designed to trick victims into executing malicious payloads under the guise of a legitimate technical assessment. This approach suggests a shift toward more targeted, strategic intrusions rather than broad, indiscriminate attacks.</p>
<p dir="auto">The technical details surrounding the two new RAT families indicate a deliberate investment in cross-platform compatibility, likely to broaden the group's targeting footprint. While the full scope of the campaign's victims is not yet public, the use of Node.js and JavaScript allows the malware to run seamlessly across operating systems, complicating detection efforts for security teams that may not have visibility into malicious scripts on non-Windows endpoints.</p>
<p dir="auto">Key takeaways from the analysis include:</p>
<ul>
<li>The threat actor, Nimbus Manticore, is now attributed to campaigns using cross-platform RATs written in Node.js and JavaScript.</li>
<li>Infection chains begin with phishing or social engineering lures, specifically themed around recruitment and coding tests.</li>
<li>The new malware families extend the group's reach to Linux and macOS systems, in addition to their previous Windows-focused operations.</li>
<li>The activity was documented by Kaspersky, though no specific CVE identifiers or patch numbers were mentioned in the initial reporting.</li>
</ul>
<p dir="auto">Affected organizations should prioritize monitoring for suspicious Node.js processes and review any unsolicited recruitment messages that request the download or execution of coding challenge files, as these may be initial infection vectors.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Does your security operations center actively monitor for malicious Node.js or JavaScript execution on Linux and macOS endpoints, or is that visibility still a blind spot in your environment?</p>
]]></description><link>https://xploitlk.com/topic/243/iranian-hackers-pose-as-recruiters-to-deliver-cross-platform-rats-through-coding-tests</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:40:52 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/243.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Sep 2026 00:30:22 GMT</pubDate><ttl>60</ttl></channel></rss>