Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
AI Summary
The Iranian threat actor Nimbus Manticore, also known as Iranian Dream Job, is using fake job recruitment lures on platforms like LinkedIn to deliver two newly identified cross-platform remote access trojans (RATs): NodeRabbit and PollCat. These malware families are distributed via trojanized coding challenge archives that contain malicious npm packages or JavaScript code, targeting developers on Windows, Linux, and macOS. The attacks enable command execution, file manipulation, persistence, and reconnaissance, with C2 infrastructure hosted on Azure and communication through specific API endpoints. The group's shift to Node.js-based cross-platform tools expands its reach while maintaining its historical social engineering tactics for cyber espionage in the Middle East and Africa.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | plugplay[.]azurewebsites[.]net | Details → |
| Domain | rgbteller[.]azurewebsites[.]net | Details → |
| Domain | wslwebui[.]azurewebsites[.]net | Details → |
| Filename | Front-Technical-Challenge.zip | Details → |
| Filename | RankChallenge-react-6uJSX3-main.zip | Details → |
| Filename | server.js | Details → |
| Filename | node_modules/.cache/.320697f1/index.js | Details → |
| Package | [email protected] | Details → |
| Package | [email protected] | Details → |
| Filename | GitHub Copilot Helper | Details → |
| Filename | ctf-server | Details → |