Iranian Hackers Pose as Recruiters to Deliver New Cross-Platform Malware

The Iranian threat group Nimbus Manticore is using trojanized coding challenges disguised as job interviews to deliver two new cross-platform RATs, NodeRabbit and PollCat, in a campaign researchers say targets critical sectors across the Middle East and Africa.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
A laptop displaying a coding assessment interface, representing the fake recruiter lures used to deliver Iranian-linked malware

A laptop displaying a coding assessment interface, representing the fake recruiter lures used to deliver Iranian-linked malware

The Iranian state-linked hacking group Nimbus Manticore, also tracked as Iranian Dream Job for its long-running use of fake recruitment lures, has expanded its toolset with two previously undocumented malware families capable of infecting Windows, Linux and macOS from a single codebase. Kaspersky, which is tracking the strains as NodeRabbit and PollCat, said the shift to cross-platform scripting gives the group's operators a unified codebase that blends into developer workstations regardless of operating system.

The infection chain follows the group's established playbook with a technical upgrade. Operators pose as talent acquisition specialists at major technology companies on LinkedIn and other job platforms, inviting targets, typically software engineers, to complete a timed coding assessment. The archive delivered as part of one observed lure, a ZIP file named "Front-Technical-Challenge.zip," contained a project management tool with instructions to fix bugs in the frontend code within three hours, while explicitly telling candidates not to touch the server component because it was "bug-free." That server file was where the malicious code lived: a trojanized npm package bundled directly in the archive rather than published to the public registry, which silently launched NodeRabbit as a background process the moment the challenge was opened.

NodeRabbit communicates with Azure-hosted command and control infrastructure and supports eleven commands covering host reconnaissance, arbitrary shell execution, file read and write operations, and network enumeration. Kaspersky identified two further NodeRabbit variants recovered from systems in Egypt and Ethiopia, one of which disguises its persistence mechanism as a Microsoft Edge update and the other as Intel's Driver and Support Assistant. A separate lure track uses fake "CTF-style" programming challenges to deliver PollCat, a second cross-platform RAT that supports twenty-two commands and searches infected machines for folders belonging to two dozen named security vendors, including Kaspersky's own products, before reporting what it finds back to the operators.

Kaspersky researcher Omar Amin linked the campaign to Nimbus Manticore based on overlaps in command structure, beacon timing and infrastructure choices with MiniFast, a backdoor previously attributed to the group, as well as its continued use of Azure Websites and Cloudflare-backed domains. The attribution places NodeRabbit and PollCat alongside a rapidly expanding arsenal the group has rolled out in recent months, including a Windows backdoor called NightLedger and a pair of custom WebSocket tunnellers. Researchers noted the recruitment-themed lure is a tactic long associated with North Korea's Lazarus Group, but one Nimbus Manticore has now run for years under its "Dream Job" branding.

What should concern GCC security teams specifically is the stated targeting. Researchers describe the delivery mechanism as consistent with the group's historical tradecraft: using recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage. That regional focus is not new for Iranian state-linked operators. Tortoiseshell, another Iranian APT group, was reported expanding its infrastructure footprint into Saudi Arabia and the UAE earlier this year, and the pattern of Iran-aligned groups probing Gulf networks has intensified as cyber operations and kinetic conflict have increasingly converged in the region.

For GCC enterprises, the practical takeaway sits with HR and technical hiring workflows rather than traditional perimeter defences. Security teams should treat unsolicited recruiter contact bearing a downloadable coding assessment as a credible phishing vector, run take-home technical challenges in sandboxed or disposable environments rather than primary developer machines, and flag any instruction that tells a candidate not to inspect a specific file as a red flag in itself.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

nation-state threat actorssocial engineering gcc enterprises