Iranian Group Nimbus Manticore Deploys Cross‑Platform RATs via Fake Coding Assessments
Security researchers have traced two previously unknown remote‑access trojans to the Iranian cyber‑espionage outfit known as Nimbus Manticore, noting that the malware is being distributed through seemingly legitimate coding tests posted by fake recruiters.
The lure works by advertising entry‑level or freelance development positions, then sending applicants a test file—often a zip or script—purported to contain a coding challenge. Once opened, the payload installs a backdoor that can operate on Windows, Linux and macOS systems, giving the attackers persistent control over the victim’s machine.
Analysts say the two malware families are distinct from the group’s earlier toolset, which primarily targeted Windows environments. Their cross‑platform design broadens the potential victim pool to include developers who work on open‑source projects, cloud‑native services, and mixed‑OS workstations.
Nimbus Manticore has been linked to Iran’s broader cyber‑operations for several years, often focusing on intellectual property theft and surveillance of dissident communities. The recent shift toward multi‑OS capabilities reflects a strategic adaptation to the increasingly heterogeneous tech stacks used by modern enterprises.
Industry observers warn that the scheme could affect a wide range of candidates, from recent graduates to seasoned engineers, because the recruitment façade mimics genuine hiring practices on popular job boards and professional networks.
Technical analysis of the trojans reveals typical RAT functionalities: encrypted command‑and‑control traffic, file exfiltration, keylogging, and the ability to execute arbitrary code. The malware also includes modules for privilege escalation on Unix‑like systems, allowing it to persist even after reboots.
Several cybersecurity firms have issued advisories urging job seekers to verify recruiter identities, scan all attachments with up‑to‑date antivirus tools, and avoid executing scripts from untrusted sources. Organizations are also being told to monitor network traffic for anomalous outbound connections that could indicate a compromised endpoint.
The emergence of cross‑platform RATs underscores a growing trend among state‑aligned groups to develop flexible payloads that can infiltrate diverse environments, complicating detection and response efforts for defenders.
Experts anticipate that Nimbus Manticore will continue to refine this recruitment‑based delivery model, leveraging the trust inherent in hiring processes to expand its reach. Vigilance in recruitment channels and robust endpoint security remain critical defenses against this evolving threat.
Comments (0)
Be the first to comment.
Join the discussion