Executive Summary
Iranian threat group Nimbus Manticore (also known as Mirage Kitten) has expanded their attack methodology by deploying cross-platform remote access trojans (RATs) through sophisticated social engineering campaigns targeting software engineers. The group poses as recruiters from major technology companies on LinkedIn and other job platforms, delivering trojanized coding challenges containing NodeRabbit and PollCat malware. These Node.js and JavaScript-based RATs can infect Windows, Linux, and macOS systems, representing a significant evolution from their traditional C/C++ toolset. The campaign has been observed targeting victims across Afghanistan, Egypt, and Ethiopia, demonstrating the group's expanded geographic reach and technical capabilities.
This incident highlights the growing trend of state-sponsored actors adopting cross-platform development frameworks to maximize their attack surface while leveraging legitimate recruitment processes as attack vectors. The sophisticated nature of these fake coding challenges and the pressure tactics employed demonstrate how threat actors are increasingly exploiting the competitive job market in the technology sector.
Why This Matters Now
The shift to cross-platform malware frameworks by state-sponsored actors represents a critical escalation in cyber espionage capabilities, allowing single codebases to target multiple operating systems while exploiting the current competitive tech job market and developer recruitment processes.
Attack Path Analysis
Iranian Nimbus Manticore group used recruitment-themed social engineering to deliver cross-platform RATs through trojanized coding challenges. Attackers established persistent backdoors on Windows, Linux, and macOS systems, maintained command and control through Azure-hosted infrastructure, and positioned for data theft while conducting reconnaissance of security vendor installations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors posed as recruiters on LinkedIn to deliver trojanized coding challenge archives containing malicious Node.js packages (colorized_terminal, pretty-log) that executed NodeRabbit and PollCat RATs when developers ran the assessment projects
MITRE ATT&CK® Techniques
Spearphishing Link
Match Legitimate Name or Location
JavaScript
Registry Run Keys / Startup Folder
Create or Modify System Process: Windows Service
Web Protocols
Data from Local System
Process Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Engineering Techniques
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02(b)
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Data Categorization and Sensitivity
Control ID: DA.L2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21.2(a)
ISO 27001 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Iranian cyber espionage targeting software engineers through fake recruitment and trojanized coding challenges compromises development environments and intellectual property.
Information Technology/IT
Cross-platform RATs targeting IT professionals through LinkedIn recruitment scams enable lateral movement, data exfiltration, and compromise of critical infrastructure.
Cybersecurity
Security professionals targeted via fake technical assessments risk compromise of security tools, client data, and threat intelligence through advanced evasion techniques.
Telecommunications
Social engineering attacks against telecom engineers through recruitment lures threaten network infrastructure, encrypted communications, and customer data through persistent backdoors.
Sources
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Testshttps://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.htmlVerified
- Mirage Kitten: new backdoors NodeRabbit and PollCathttps://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/Verified
- Iranian Dream Job Campaign Delivers New Malwarehttps://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.htmlVerified
- Nimbus Manticore Expands Toolset with New Cross-Platform Capabilitieshttps://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the scope of this Iranian Nimbus Manticore campaign by constraining cross-platform lateral movement and controlling egress channels used for C2 communications and data exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud workload isolation policies would likely limit the initial malware's ability to communicate with external command infrastructure and reduce its reach across cloud-native development environments
Control: Zero Trust Segmentation
Mitigation: Workload-level segmentation would likely reduce the malware's ability to establish persistent access across multiple system types and limit its privilege escalation scope within segmented environments
Control: East-West Traffic Security
Mitigation: East-west traffic enforcement would likely limit the malware's ability to move laterally across different operating systems and development environments, reducing its overall network reach and cross-platform propagation capabilities
Control: Multicloud Visibility & Control
Mitigation: Multicloud traffic inspection would likely detect and constrain the backdoors' REST API communications with Azure-hosted C2 infrastructure, reducing the attackers' ability to maintain persistent command channels
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely limit the malware's ability to exfiltrate large Outlook files and Git repository data by constraining unauthorized outbound data transfers to external Azure infrastructure
While reconnaissance activities may still occur within individual workloads, the overall impact scope would likely be significantly reduced due to constrained lateral movement and limited data exfiltration capabilities
Impact at a Glance
Affected Business Functions
- Software Development Operations
- Intellectual Property Protection
- Source Code Management
- Developer Workstation Security
Estimated downtime: 3 days
Estimated loss: N/A
Potential exposure of proprietary source code, development credentials, Git repositories, email artifacts from Outlook OST/PST files, and intellectual property from compromised developer workstations. The malware specifically targets software development environments and can harvest sensitive development-related information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation to prevent lateral movement between developer workstations and production environments
- • Deploy egress security controls with FQDN filtering to detect and block C2 communications to suspicious Azure domains
- • Enable multicloud visibility to monitor anomalous outbound connections and file transfer activities from development systems
- • Establish threat detection capabilities to identify suspicious Node.js processes and persistence mechanism installations
- • Enforce encrypted traffic inspection to detect malicious payloads within development tools and coding challenge archives



