The Iranian hacking group known as Nimbus Manticore has recently been linked to two new malware families, indicating an expansion in their technological capabilities. These developments suggest a broadened target range, now including Linux and Apple macOS systems, through the deployment of cross-platform remote access trojans (RATs) built with Node.js and JavaScript.
New Malware Strains and Their Origins
Russian cybersecurity firm Kaspersky has identified the malware strains as NodeRabbit and PollCat. The initial discovery of NodeRabbit was on a system in Afghanistan, followed by detections on machines in Egypt and Ethiopia. According to Kaspersky researcher Omar Amin, the malware is distributed through spear-phishing on platforms like LinkedIn, disguised as coding challenges.
Unlike their previous reliance on malware written in C, C++, and Go, Nimbus Manticore has ventured into cross-platform tools. This marks a significant step in their malware evolution, with NodeRabbit and PollCat being the latest additions to their arsenal.
Malware Delivery and Functionality
The infiltration begins with a ZIP file posing as a coding challenge, allegedly from a major tech company. This file includes a project management tool called Taskflow, inviting candidates to debug it without using AI tools. The malicious code is embedded in the supposedly bug-free server component, server.js, which imports a trojanized npm package.
NodeRabbit communicates with command-and-control (C2) servers hosted on Azure, supporting numerous commands to gather system information and execute various tasks. Variants of NodeRabbit have been found in Egypt and Ethiopia, each employing different npm packages and API endpoints.
PollCat’s Role and Connections
PollCat, another malware family used by Nimbus Manticore, is deployed through developer assessments with a time-limited challenge. It operates independently of the success of a one-time password validation, creating a sense of urgency to increase infection rates.
PollCat establishes persistence on multiple operating systems and communicates with C2 servers through various API endpoints. It can perform extensive operations, including file management and process enumeration. The malware is designed to inventory specific software and security vendor folders, sending the results back to the attackers.
Kaspersky links these activities to Nimbus Manticore based on structural similarities and shared infrastructure with previous operations. The shift to cross-platform scripting demonstrates a strategic move to target developer environments across different systems.
The tactics used by Nimbus Manticore, such as impersonating recruiters on LinkedIn, continue to pose significant threats to sectors across the Middle East and Africa. These developments underscore the need for heightened vigilance and robust cybersecurity measures.
