Ethical Hacking News
Iranian Hackers Use Recruitment-Themed Lures to Deliver Advanced Cross-Platform Malware
A new threat actor has been identified as using sophisticated tactics to deliver cross-platform malware to potential victims. The malware, which has been attributed to the Iranian hacking group known as Nimbus Manticore, has been found to use recruitment-themed lures to trick victims into installing a remote access trojan (RAT) on their systems.
Nimbus Manticore, an Iranian hacking group, has been using recruitment-themed lures to deliver advanced cross-platform malware to potential victims. The malware, known as NodeRabbit and PollCat, has been found to possess a range of capabilities, including gathering host details, listing running processes, and executing arbitrary shell commands. The malware communicates with a command-and-control (C2) server through three distinct API endpoints, allowing it to perform a range of malicious activities. The use of cross-platform scripting by Nimbus Manticore has given the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The cybersecurity landscape has recently witnessed a significant escalation in the tactics employed by Iranian hackers, specifically the hacking group known as Nimbus Manticore. This threat actor has been identified as using recruitment-themed lures to deliver advanced cross-platform malware to potential victims. The malware, which has been attributed to Nimbus Manticore, has been found to use sophisticated techniques to compromise the security of systems running on various operating systems, including Windows, Linux, and Apple macOS.
According to recent reports, Nimbus Manticore has been using spear-phishing messages on LinkedIn and other job search platforms to deliver the malware. The messages allegedly contain trojanized coding challenge archives that, when opened, launch the malware on the victim's system. The malware, which has been identified as NodeRabbit and PollCat, has been found to possess a range of capabilities, including the ability to gather host details, list running processes, execute arbitrary shell commands, and enumerate directories.
The NodeRabbit malware has been found to communicate with a command-and-control (C2) server through three distinct API endpoints, including /api/rabbit/checkin, /api/rabbit/task, and /api/rabbit/result. The malware supports 11 commands, which allows it to perform a range of malicious activities, including gathering host details, listing running processes, and executing arbitrary shell commands. The NodeRabbit malware has also been found to possess a unique capability, known as "write a Base64-encoded Node.js script to a randomly named .tmp file, execute it, and then delete it to cover up traces of malicious activity."
In addition to NodeRabbit, Nimbus Manticore has also been identified as using the PollCat malware to compromise systems. The PollCat malware has been found to possess a range of capabilities, including the ability to gather host details, list running processes, execute arbitrary shell commands, and enumerate directories. The PollCat malware has also been found to communicate with a C2 server through seven API endpoints, including /beacon, /gate/hello, /gate/fetch, /vault, /vault/push, /gate/track, and /sdk/v2/ready.
The PollCat malware has been found to possess a range of unique capabilities, including the ability to create daily scheduled tasks on Windows, Linux, or macOS, and to connect to a C2 server to send basic host information and await further instructions. The malware has also been found to support 22 commands, which allows it to perform a range of malicious activities, including file operations, process management, and network communication.
The delivery mechanism used by Nimbus Manticore to deliver the malware has been found to be consistent with the group's historical tradecraft. The group has allegedly used recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage purposes. The use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The shift to cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on Windows, Linux, and macOS, with payloads that blend naturally into developer workstations. The development also comes amid a rapid expansion of the hacking group's malware arsenal in recent months, including a Windows backdoor called NightLedger, two custom WebSocket tunnelers, BridgeHead and ArcBridge, a reverse SSH tunneling tool, and a backdoor that shares overlaps with TWOSTROKE.
The activity's links to Nimbus Manticore stem from the structural, command fetching, beacon timing, and command set similarities between PollCat and MiniFast, a backdoor previously attributed to the group, as well as the use of Azure Websites and Cloudflare-backed domains for C2.
The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems.
In conclusion, the recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the sophistication and creativity of the group's tactics. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The recent findings on Nimbus Manticore's malware arsenal highlight the rapid expansion of the group's capabilities in recent months. The development also comes amid a shift in the threat actor's tactics, with the group now using cross-platform scripting to compromise systems running on various operating systems. The use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware have highlighted the sophistication and creativity of the group's tactics. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The threat landscape continues to evolve, with new threats emerging every day. The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the importance of staying vigilant and proactive in the face of emerging threats. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
In the ever-evolving threat landscape, it is essential to stay informed and up-to-date on the latest threats and tactics. The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the importance of staying vigilant and proactive in the face of emerging threats. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The threat landscape continues to evolve, with new threats emerging every day. The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the importance of staying vigilant and proactive in the face of emerging threats. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware have highlighted the sophistication and creativity of the group's tactics. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
In the ever-evolving threat landscape, it is essential to stay informed and up-to-date on the latest threats and tactics. The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the importance of staying vigilant and proactive in the face of emerging threats. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The recent findings on Nimbus Manticore's malware arsenal highlight the rapid expansion of the group's capabilities in recent months. The development also comes amid a shift in the threat actor's tactics, with the group now using cross-platform scripting to compromise systems running on various operating systems. The use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
In conclusion, the recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the sophistication and creativity of the group's tactics. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
The threat landscape continues to evolve, with new threats emerging every day. The recent reports on Nimbus Manticore's use of recruitment-themed lures to deliver advanced cross-platform malware highlight the importance of staying vigilant and proactive in the face of emerging threats. The use of cross-platform scripting by Nimbus Manticore has been found to give the operators a single codebase that runs on various operating systems, allowing them to compromise systems running on these operating systems. The threat actor's use of recruitment-themed lures to deliver the malware has been found to be a sophisticated tactic, designed to trick victims into installing the malware on their systems.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Rise-of-Nimbus-Manticore-How-Iranian-Hackers-Are-Expanding-Their-Malware-Arsenal-ehn.shtml
https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
https://cybersecuritynews.com/fake-coding-tests/
Published: Tue Sep 1 09:17:44 2026 by llama3.2 3B Q4_K_M