TechNewsReel
Live

Iranian Group Nimbus Manticore Targets Developers With Cross-Platform RATs

The threat actor poses as recruiters to deliver Node.js-based malware via fake coding tests.

TechNewsReel Newsroom · September 1, 2026

The Iranian hacking group Nimbus Manticore is targeting software developers through a sophisticated social engineering campaign that leverages fake job opportunities. By posing as recruiters, the group is successfully delivering cross-platform Remote Access Trojans (RATs) to high-value targets.

According to reports from The Hacker News and cybersecurity researchers, the attackers initiate contact with candidates and request they complete technical assessments. These assessments are delivered as archives, such as 'Front-Technical-Challenge.zip,' which contain malware. Once executed, the attack deploys two previously undocumented malware families known as NodeRabbit and PollCat. Developed using Node.js and JavaScript, these tools allow the attackers to maintain persistence and control over infected systems.

A Strategic Shift in Tooling

Nimbus Manticore—also tracked as Mirage Kitten, UNC1549, and Smoke Sandstorm—is an Iranian-linked threat actor primarily focused on espionage. The transition to Node.js-based malware represents a calculated strategic shift. By utilizing JavaScript, the group can maintain a single codebase that functions across Windows, Linux, and macOS. This versatility eliminates the need to develop separate payloads for different operating systems, significantly streamlining their deployment process.

Implications for Corporate Security

This campaign is particularly dangerous because it exploits the professional aspirations of developers, a group typically well-versed in security. By embedding the RATs within a familiar workflow—the coding test—the attackers bypass traditional psychological defenses. Furthermore, the use of cross-platform languages makes detection more difficult for legacy security tools that are optimized for OS-specific signatures. As corporate environments increasingly rely on diverse hardware and OS ecosystems, the ability for a single piece of malware to pivot across a network regardless of the platform increases the risk of widespread compromise.

Future Outlook

Security teams are advised to treat unsolicited recruitment outreach with extreme caution, particularly when it involves downloading and executing local archives for technical tests. While the current campaign focuses on NodeRabbit and PollCat, the group's move toward versatile, cross-platform frameworks suggests that future iterations of their toolset will likely become more modular and harder to fingerprint. Analysts continue to monitor the group's infrastructure to determine the full scale of the breach and the specific data targeted during these intrusions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.