Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Iranian Hackers Use Job Offers to Spread Cross-Platform Malware

Posted on September 1, 2026 By CWS

The Iranian hacking group known as Nimbus Manticore has recently been linked to two new malware families, indicating an expansion in their technological capabilities. These developments suggest a broadened target range, now including Linux and Apple macOS systems, through the deployment of cross-platform remote access trojans (RATs) built with Node.js and JavaScript.

New Malware Strains and Their Origins

Russian cybersecurity firm Kaspersky has identified the malware strains as NodeRabbit and PollCat. The initial discovery of NodeRabbit was on a system in Afghanistan, followed by detections on machines in Egypt and Ethiopia. According to Kaspersky researcher Omar Amin, the malware is distributed through spear-phishing on platforms like LinkedIn, disguised as coding challenges.

Unlike their previous reliance on malware written in C, C++, and Go, Nimbus Manticore has ventured into cross-platform tools. This marks a significant step in their malware evolution, with NodeRabbit and PollCat being the latest additions to their arsenal.

Malware Delivery and Functionality

The infiltration begins with a ZIP file posing as a coding challenge, allegedly from a major tech company. This file includes a project management tool called Taskflow, inviting candidates to debug it without using AI tools. The malicious code is embedded in the supposedly bug-free server component, server.js, which imports a trojanized npm package.

NodeRabbit communicates with command-and-control (C2) servers hosted on Azure, supporting numerous commands to gather system information and execute various tasks. Variants of NodeRabbit have been found in Egypt and Ethiopia, each employing different npm packages and API endpoints.

PollCat’s Role and Connections

PollCat, another malware family used by Nimbus Manticore, is deployed through developer assessments with a time-limited challenge. It operates independently of the success of a one-time password validation, creating a sense of urgency to increase infection rates.

PollCat establishes persistence on multiple operating systems and communicates with C2 servers through various API endpoints. It can perform extensive operations, including file management and process enumeration. The malware is designed to inventory specific software and security vendor folders, sending the results back to the attackers.

Kaspersky links these activities to Nimbus Manticore based on structural similarities and shared infrastructure with previous operations. The shift to cross-platform scripting demonstrates a strategic move to target developer environments across different systems.

The tactics used by Nimbus Manticore, such as impersonating recruiters on LinkedIn, continue to pose significant threats to sectors across the Middle East and Africa. These developments underscore the need for heightened vigilance and robust cybersecurity measures.

The Hacker News Tags:Apple macOS malware, cross-platform malware, cyber espionage, Cybersecurity, digital security, Iranian hackers, Kaspersky, LinkedIn scams, Linux malware, Nimbus Manticore, Node.js malware, NodeRabbit, PollCat, Remote Access Trojans, spear-phishing

Post navigation

Previous Post: Exploit Released for Microsoft Exchange Server RCE Vulnerability
Next Post: AI Utilized to Transfer PLC Exploit, Cost and Time Intensive

Related Posts

Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers The Hacker News
Optimize Your SOC: Build, Buy, or Automate? Optimize Your SOC: Build, Buy, or Automate? The Hacker News
Turning BIA Insights Into Resilient Recovery Turning BIA Insights Into Resilient Recovery The Hacker News
Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to 2M in Damages Scattered Spider Behind Cyberattacks on M&S and Co-op, Causing Up to $592M in Damages The Hacker News
UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors The Hacker News
Linux Kernel Vulnerability Exposes Root Access Risk Linux Kernel Vulnerability Exposes Root Access Risk The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • UK Introduces Passkeys for 23 Million GOV.UK Users
  • 3BB Network Breach: MeshCentral Backdoor Exploited
  • Massive Vite Server Vulnerability Exploited for Cloud Credential Theft
  • Red Heron Uses Gitea Exploit to Breach Global Firms
  • Hackers Target FortiGate VPN Vulnerability in Thai Broadband Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark