By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Iranian Hackers Deliver Cross-Platform RATs Via Coding Tests

The Iranian hacking group Nimbus Manticore has been identified by Russian cybersecurity firm Kaspersky as the perpetrator behind two new malware families. These families represent a significant evolution in the group's capabilities, particularly in their ability to develop cross-platform remote access trojans (RATs) using Node.js and JavaScript. This technological advancement allows Nimbus Manticore to expand its targeting beyond Windows systems to include Linux and Apple macOS environments, a notable expansion of their operational reach. The group's modus operandi involves posing as legitimate recruiters and enticing potential victims with seemingly innocuous coding tests. These tests, however, are booby-trapped with malicious payloads designed to compromise the target's system.
Kaspersky's analysis, detailed in a report published on March 13, 2024, highlights that the group has been active since at least September 2023. The newly discovered malware families, which have not yet been assigned specific public names by Kaspersky, are built with a modular architecture. This design allows for flexibility and adaptability, enabling the attackers to tailor their tools for specific campaigns and targets. The use of Node.js and JavaScript for developing these RATs is a strategic choice, as these technologies are widely used in web development and can be compiled to run on multiple operating systems, facilitating the cross-platform infection strategy. This approach bypasses the need for separate malware variants for each operating system, streamlining the attack process and increasing efficiency.
The lure of coding tests is particularly effective in the tech industry, where recruitment often involves such assessments. By presenting these tests as part of a legitimate hiring process, Nimbus Manticore can exploit the trust and eagerness of developers and other tech professionals. Once a victim downloads and executes the coding test, the RAT is installed, granting the attackers remote access to the compromised system. This access can then be leveraged for various malicious activities, including data theft, espionage, or further network infiltration. The sophistication of this social engineering tactic, combined with advanced cross-platform malware, underscores the evolving threat landscape posed by state-sponsored or state-affiliated hacking groups.
Kaspersky's research indicates that Nimbus Manticore has been observed deploying these tools in targeted campaigns, suggesting a focus on specific organizations or individuals. While the exact motivations and ultimate objectives of these attacks are not fully detailed, the deployment of RATs typically points towards intelligence gathering, intellectual property theft, or disruption. The group's consistent activity since at least September 2023 and the development of novel, cross-platform malware demonstrate a persistent and evolving threat. The cybersecurity community is advised to be vigilant against such sophisticated social engineering tactics, especially those involving unsolicited coding challenges or recruitment offers from unknown entities. Enhanced endpoint security, user awareness training, and rigorous verification of recruitment processes are crucial countermeasures against these evolving threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.