hacker-news · Crawled Sep 2, 2026

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

11 IoCs 1 Actors
Read original article ↗

AI Summary

The Iranian threat actor Nimbus Manticore, also known as Iranian Dream Job, is using fake job recruitment lures on platforms like LinkedIn to deliver two newly identified cross-platform remote access trojans (RATs): NodeRabbit and PollCat. These malware families are distributed via trojanized coding challenge archives that contain malicious npm packages or JavaScript code, targeting developers on Windows, Linux, and macOS. The attacks enable command execution, file manipulation, persistence, and reconnaissance, with C2 infrastructure hosted on Azure and communication through specific API endpoints. The group's shift to Node.js-based cross-platform tools expands its reach while maintaining its historical social engineering tactics for cyber espionage in the Middle East and Africa.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 11 extracted

Type Value Detail
Domain plugplay[.]azurewebsites[.]net Details →
Domain rgbteller[.]azurewebsites[.]net Details →
Domain wslwebui[.]azurewebsites[.]net Details →
Filename Front-Technical-Challenge.zip Details →
Filename RankChallenge-react-6uJSX3-main.zip Details →
Filename server.js Details →
Filename node_modules/.cache/.320697f1/index.js Details →
Package [email protected] Details →
Package [email protected] Details →
Filename GitHub Copilot Helper Details →
Filename ctf-server Details →

MITRE ATT&CK TTPs 27 techniques