The record
Written from the 1 report below. Nothing here is unsourced.
- Kaspersky researchers attribute two new cross-platform malware families, NodeRabbit and PollCat, to the Iranian hacking group Nimbus Manticore, which tricks software developers through fake coding tests sent via LinkedIn and job platforms.
- Victims are asked to fix bugs in a project as part of a supposed hiring challenge, while malicious code hidden in a supposedly off-limits server file installs a remote access trojan.
- The malware works on Windows, Linux, and macOS, can run commands, steal data, and persist by disguising itself as legitimate software updates.
- The findings show the group expanding its tools beyond Windows and adding to a rapidly growing malware arsenal.
What to watch next
- Whether NodeRabbit or PollCat samples appear in more countries beyond Afghanistan, Egypt, and Ethiopia
- Further evolution of Nimbus Manticore's cross-platform malware and fake recruitment lures
- Possible takedowns or blocking of the Azure-hosted command-and-control servers and trojanized npm packages
Coverage1
1 report
English national1
All filed from India
Named Afghanistan · Egypt · Ethiopia · GitHub Copilot · Intel · Microsoft Edge · VS Code · Amazon Web Services · Azure · Cloudflare · Kaspersky · Lazarus Group · Mirage Kitten · Nimbus Manticore · Omar Amin
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
