Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Posted on September 1, 2026 By CWS

The Iranian hacking group known as Nimbus Manticore has recently been linked to two new malware families, indicating an expansion in their technological capabilities. These developments suggest a broadened target range, now including Linux and Apple macOS systems, through the deployment of cross-platform remote access trojans (RATs) built with Node.js and JavaScript.

New Malware Strains and Their Origins

Russian cybersecurity firm Kaspersky has identified the malware strains as NodeRabbit and PollCat. The initial discovery of NodeRabbit was on a system in Afghanistan, followed by detections on machines in Egypt and Ethiopia. According to Kaspersky researcher Omar Amin, the malware is distributed through spear-phishing on platforms like LinkedIn, disguised as coding challenges.

Unlike their previous reliance on malware written in C, C++, and Go, Nimbus Manticore has ventured into cross-platform tools. This marks a significant step in their malware evolution, with NodeRabbit and PollCat being the latest additions to their arsenal.

Malware Delivery and Functionality

The infiltration begins with a ZIP file posing as a coding challenge, allegedly from a major tech company. This file includes a project management tool called Taskflow, inviting candidates to debug it without using AI tools. The malicious code is embedded in the supposedly bug-free server component, server.js, which imports a trojanized npm package.

NodeRabbit communicates with command-and-control (C2) servers hosted on Azure, supporting numerous commands to gather system information and execute various tasks. Variants of NodeRabbit have been found in Egypt and Ethiopia, each employing different npm packages and API endpoints.

PollCat’s Role and Connections

PollCat, another malware family used by Nimbus Manticore, is deployed through developer assessments with a time-limited challenge. It operates independently of the success of a one-time password validation, creating a sense of urgency to increase infection rates.

PollCat establishes persistence on multiple operating systems and communicates with C2 servers through various API endpoints. It can perform extensive operations, including file management and process enumeration. The malware is designed to inventory specific software and security vendor folders, sending the results back to the attackers.

Kaspersky links these activities to Nimbus Manticore based on structural similarities and shared infrastructure with previous operations. The shift to cross-platform scripting demonstrates a strategic move to target developer environments across different systems.

The tactics used by Nimbus Manticore, such as impersonating recruiters on LinkedIn, continue to pose significant threats to sectors across the Middle East and Africa. These developments underscore the need for heightened vigilance and robust cybersecurity measures.

The Hacker News Tags:Apple macOS malware, cross-platform malware, cyber espionage, Cybersecurity, digital security, Iranian hackers, Kaspersky, LinkedIn scams, Linux malware, Nimbus Manticore, Node.js malware, NodeRabbit, PollCat, Remote Access Trojans, spear-phishing

Post navigation

Previous Post: Exploit Released for Microsoft Exchange Server RCE Vulnerability
Next Post: AI Utilized to Transfer PLC Exploit, Cost and Time Intensive

Related Posts

Why CISOs Must Rethink Incident Remediation Why CISOs Must Rethink Incident Remediation The Hacker News
AI-Based Phishing Scheme Targets Apple Device Owners AI-Based Phishing Scheme Targets Apple Device Owners The Hacker News
SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics SCMBANKER Malware Targets Mexican Banks with ClickFix Tactics The Hacker News
New ClickFix Variant Exploits Network Drives New ClickFix Variant Exploits Network Drives The Hacker News
Critical Cisco Flaw Exploited, Causes Remote DoS Risks Critical Cisco Flaw Exploited, Causes Remote DoS Risks The Hacker News
ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners ShadowCaptcha Exploits WordPress Sites to Spread Ransomware, Info Stealers, and Crypto Miners The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Five Hackers Admit to ATM Malware Attacks in Kansas
  • Venezuelan Nationals Admit to ATM Jackpotting in US
  • Stealthy Windows Backdoor Evades Detection Until Triggered
  • AI Utilized to Transfer PLC Exploit, Cost and Time Intensive
  • Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Five Hackers Admit to ATM Malware Attacks in Kansas
  • Venezuelan Nationals Admit to ATM Jackpotting in US
  • Stealthy Windows Backdoor Evades Detection Until Triggered
  • AI Utilized to Transfer PLC Exploit, Cost and Time Intensive
  • Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark