Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the
- 1. The Iranian Nimbus Manticore hacking group is employing cross-platform remote access trojans (RATs) written in Node.js and JavaScript, named NodeRabbit and PollCat, to infect Linux and Apple macOS systems.
- 2. These malware strains are delivered through spear-phishing messages on platforms like LinkedIn, disguised as coding challenge archives for job recruitment.
- 3. The group's toolset has rapidly expanded, including a Windows backdoor (NightLedger), WebSocket tunnelers (BridgeHead, ArcBridge), a reverse SSH tunneling tool, and a backdoor with overlaps with TWOSTROKE.
Article analysis
Skim this article about "Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests": 3 key takeaways and more.
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
skim AI Analysis | The Hacker News
The Hacker News on Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests: skim's analysis surfaces 3 key takeaways. Iranian hackers, Nimbus Manticore, are using cross-platform RATs (NodeRabbit, PollCat) delivered via fake coding tests on job platforms. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Tech. News article analyzed by skim.
Summary
Iranian hackers, Nimbus Manticore, are using cross-platform RATs (NodeRabbit, PollCat) delivered via fake coding tests on job platforms. These RATs, written in Node.js and JavaScript, target Linux and macOS, expanding their capabilities beyond previous Windows-based malware.
Key Takeaways
- The Iranian Nimbus Manticore hacking group is employing cross-platform remote access trojans (RATs) written in Node.js and JavaScript, named NodeRabbit and PollCat, to infect Linux and Apple macOS systems.
- These malware strains are delivered through spear-phishing messages on platforms like LinkedIn, disguised as coding challenge archives for job recruitment.
- The group's toolset has rapidly expanded, including a Windows backdoor (NightLedger), WebSocket tunnelers (BridgeHead, ArcBridge), a reverse SSH tunneling tool, and a backdoor with overlaps with TWOSTROKE.
Statement Breakdown
- Claimed Facts: 70% of statements the article presents as facts
- Opinions: 20% of statements classified as editorial or subjective
- Claims: 10% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The article relies on a reputable cybersecurity firm for its technical analysis and attribution. It provides specific details about malware families, delivery methods, and command-and-control infrastructure. The information is presented factually, with clear attribution to the source of the findings.
Bias assessment: Technical Reporting. The article focuses on the technical aspects of a cyber threat, detailing the methods and tools used by a hacking group. It avoids sensationalism or emotional language, presenting the information in a straightforward, analytical manner.
Note: This article provides a detailed technical analysis of a cyber threat. Readers should consider the source's expertise and the technical nature of the information presented.
Credibility flag: Technical Analysis
Claimed Facts (10)
- This is a direct statement of fact about the attribution of new malware to a specific hacking group and its technical characteristics.
- This is a factual statement about the naming conventions used by a cybersecurity firm for the identified malware.
- This provides specific geographical locations and the order of discovery for a malware sample.
- This contrasts past technical methods with current ones, presenting a factual observation of the threat actor's evolution.
- This details the technical infrastructure and communication methods of the malware, presented as factual observations.
- This states the discovery of additional malware variants and their origins, presented as a factual finding.
- This describes the technical mechanisms used by the malware for maintaining persistence across different operating systems.
- This is a factual statement about another observed delivery method for a different malware strain by the same group.
- This describes the user-facing interaction within the malicious archive, presented as a factual observation of the process.
- This details the persistence mechanisms and initial communication of the PollCat malware.
Opinions (8)
- While presented as a fact, the phrasing 'Its operators deliver' implies an interpretation of intent and action by the group, bordering on an opinion about their operational methods.
- The statement 'it is written in obfuscated JavaScript' is a factual description, but the overall comparison and categorization as a RAT could be seen as an expert opinion based on analysis.
- The phrase 'it's worth noting' introduces a comparative observation and highlights a tactic, which leans towards an analytical opinion rather than a pure fact.
- The word 'claiming' suggests an interpretation of the instructions' intent and purpose, which is an opinion about the nature of the provided information.
- The use of 'likely an attempt' and 'false sense of urgency' indicates an interpretation of the threat actor's motives and strategy, which is an opinion.
- The phrase 'One possible explanation' clearly indicates speculation and an opinion about the origin of the code.
- While based on observation, the statement that it 'runs independently' and is 'unaffected' is an interpretation of the malware's behavior and design.
- This is a factual observation of the malware's capabilities, but the phrasing 'currently not implemented' implies a judgment about its state of development, which is an opinion.
Claims (10)
- While this describes a technical action, the word 'attackers' frames the actors in a way that implies malicious intent without direct proof of the intent behind this specific bundling method, making it a slightly dubious claim in its framing.
- The word 'silently' implies a hidden action that is difficult to verify directly from the text, and while likely true in context, it adds a layer of unverified stealth.
- The phrase 'is said to have' indicates that this information is reported and not directly verified by the article's author, making it a claim that relies on hearsay.
- The specific instruction to avoid AI-assisted tools, while potentially true, could be a fabricated detail or an exaggeration to emphasize the 'challenge' aspect, making it a potentially dubious claim.
- The claim that the server component is 'bug-free and functions correctly' is presented as a direct quote from the instructions, but the authenticity and accuracy of this claim within the context of a malicious lure are questionable.
- This is a very extensive list of capabilities. While likely true, the sheer breadth and detail can sometimes be an exaggeration or include functionalities that are not fully implemented or tested, making it a claim that requires deeper verification.
- The phrase 'cover up traces of malicious activity' is an interpretation of the intent behind the action, which is not directly observable and thus a dubious claim about the purpose.
- The claim that it 'does not impersonate any legitimate software' is a negative assertion that is hard to definitively prove and could be an oversight or a simplification.
- The specific timing of '10 a.m.' for a daily task might be an assumption or a detail that is not universally fixed, making it a potentially dubious claim.
- Similar to the 11 commands for NodeRabbit, a list of 22 commands is extensive and could be an overstatement or include very minor functionalities, making it a claim that warrants scrutiny.
Key Sources
- The Hacker News — Cybersecurity News Outlet
- Kaspersky — Cybersecurity Company
- Omar Amin — Security Researcher at Kaspersky
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 1st September 2026.