Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Posted on September 1, 2026 By CWS

The Iranian hacking group known as Nimbus Manticore has recently been linked to two new malware families, indicating an expansion in their technological capabilities. These developments suggest a broadened target range, now including Linux and Apple macOS systems, through the deployment of cross-platform remote access trojans (RATs) built with Node.js and JavaScript.

New Malware Strains and Their Origins

Russian cybersecurity firm Kaspersky has identified the malware strains as NodeRabbit and PollCat. The initial discovery of NodeRabbit was on a system in Afghanistan, followed by detections on machines in Egypt and Ethiopia. According to Kaspersky researcher Omar Amin, the malware is distributed through spear-phishing on platforms like LinkedIn, disguised as coding challenges.

Unlike their previous reliance on malware written in C, C++, and Go, Nimbus Manticore has ventured into cross-platform tools. This marks a significant step in their malware evolution, with NodeRabbit and PollCat being the latest additions to their arsenal.

Malware Delivery and Functionality

The infiltration begins with a ZIP file posing as a coding challenge, allegedly from a major tech company. This file includes a project management tool called Taskflow, inviting candidates to debug it without using AI tools. The malicious code is embedded in the supposedly bug-free server component, server.js, which imports a trojanized npm package.

NodeRabbit communicates with command-and-control (C2) servers hosted on Azure, supporting numerous commands to gather system information and execute various tasks. Variants of NodeRabbit have been found in Egypt and Ethiopia, each employing different npm packages and API endpoints.

PollCat’s Role and Connections

PollCat, another malware family used by Nimbus Manticore, is deployed through developer assessments with a time-limited challenge. It operates independently of the success of a one-time password validation, creating a sense of urgency to increase infection rates.

PollCat establishes persistence on multiple operating systems and communicates with C2 servers through various API endpoints. It can perform extensive operations, including file management and process enumeration. The malware is designed to inventory specific software and security vendor folders, sending the results back to the attackers.

Kaspersky links these activities to Nimbus Manticore based on structural similarities and shared infrastructure with previous operations. The shift to cross-platform scripting demonstrates a strategic move to target developer environments across different systems.

The tactics used by Nimbus Manticore, such as impersonating recruiters on LinkedIn, continue to pose significant threats to sectors across the Middle East and Africa. These developments underscore the need for heightened vigilance and robust cybersecurity measures.

The Hacker News Tags:Apple macOS malware, cross-platform malware, cyber espionage, Cybersecurity, digital security, Iranian hackers, Kaspersky, LinkedIn scams, Linux malware, Nimbus Manticore, Node.js malware, NodeRabbit, PollCat, Remote Access Trojans, spear-phishing

Post navigation

Previous Post: Exploit Released for Microsoft Exchange Server RCE Vulnerability
Next Post: AI Utilized to Transfer PLC Exploit, Cost and Time Intensive

Related Posts

AI Memory Poisoning: The Threat of Hidden Prompts AI Memory Poisoning: The Threat of Hidden Prompts The Hacker News
Patchwork Targets Turkish Defense Firms with Spear-Phishing Using Malicious LNK Files Patchwork Targets Turkish Defense Firms with Spear-Phishing Using Malicious LNK Files The Hacker News
30,000 Facebook Accounts Hacked in Phishing Scam 30,000 Facebook Accounts Hacked in Phishing Scam The Hacker News
Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution The Hacker News
Malicious Chrome Extensions Target Google and Telegram Data Malicious Chrome Extensions Target Google and Telegram Data The Hacker News
AI-Driven Phishing Toolkit Uncovered in WebDAV Campaign AI-Driven Phishing Toolkit Uncovered in WebDAV Campaign The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Stealthy Windows Backdoor Evades Detection Until Triggered
  • AI Utilized to Transfer PLC Exploit, Cost and Time Intensive
  • Iranian Hackers Use Job Offers to Spread Cross-Platform Malware
  • Exploit Released for Microsoft Exchange Server RCE Vulnerability
  • Hackers Target Langflow with Critical Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Stealthy Windows Backdoor Evades Detection Until Triggered
  • AI Utilized to Transfer PLC Exploit, Cost and Time Intensive
  • Iranian Hackers Use Job Offers to Spread Cross-Platform Malware
  • Exploit Released for Microsoft Exchange Server RCE Vulnerability
  • Hackers Target Langflow with Critical Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark