Executive Summary

Iranian threat group Nimbus Manticore (also known as Mirage Kitten) has expanded their attack methodology by deploying cross-platform remote access trojans (RATs) through sophisticated social engineering campaigns targeting software engineers. The group poses as recruiters from major technology companies on LinkedIn and other job platforms, delivering trojanized coding challenges containing NodeRabbit and PollCat malware. These Node.js and JavaScript-based RATs can infect Windows, Linux, and macOS systems, representing a significant evolution from their traditional C/C++ toolset. The campaign has been observed targeting victims across Afghanistan, Egypt, and Ethiopia, demonstrating the group's expanded geographic reach and technical capabilities.

This incident highlights the growing trend of state-sponsored actors adopting cross-platform development frameworks to maximize their attack surface while leveraging legitimate recruitment processes as attack vectors. The sophisticated nature of these fake coding challenges and the pressure tactics employed demonstrate how threat actors are increasingly exploiting the competitive job market in the technology sector.

Why This Matters Now

The shift to cross-platform malware frameworks by state-sponsored actors represents a critical escalation in cyber espionage capabilities, allowing single codebases to target multiple operating systems while exploiting the current competitive tech job market and developer recruitment processes.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organizations should implement email security controls, educate employees about suspicious recruitment messages, and establish secure processes for technical assessments that include code review and sandboxed execution environments.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the scope of this Iranian Nimbus Manticore campaign by constraining cross-platform lateral movement and controlling egress channels used for C2 communications and data exfiltration.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud workload isolation policies would likely limit the initial malware's ability to communicate with external command infrastructure and reduce its reach across cloud-native development environments

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload-level segmentation would likely reduce the malware's ability to establish persistent access across multiple system types and limit its privilege escalation scope within segmented environments

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic enforcement would likely limit the malware's ability to move laterally across different operating systems and development environments, reducing its overall network reach and cross-platform propagation capabilities

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud traffic inspection would likely detect and constrain the backdoors' REST API communications with Azure-hosted C2 infrastructure, reducing the attackers' ability to maintain persistent command channels

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress policy enforcement would likely limit the malware's ability to exfiltrate large Outlook files and Git repository data by constraining unauthorized outbound data transfers to external Azure infrastructure

Impact (Mitigations)

While reconnaissance activities may still occur within individual workloads, the overall impact scope would likely be significantly reduced due to constrained lateral movement and limited data exfiltration capabilities

Impact at a Glance

Affected Business Functions

  • Software Development Operations
  • Intellectual Property Protection
  • Source Code Management
  • Developer Workstation Security
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of proprietary source code, development credentials, Git repositories, email artifacts from Outlook OST/PST files, and intellectual property from compromised developer workstations. The malware specifically targets software development environments and can harvest sensitive development-related information.

Recommended Actions

  • Implement Zero Trust segmentation to prevent lateral movement between developer workstations and production environments
  • Deploy egress security controls with FQDN filtering to detect and block C2 communications to suspicious Azure domains
  • Enable multicloud visibility to monitor anomalous outbound connections and file transfer activities from development systems
  • Establish threat detection capabilities to identify suspicious Node.js processes and persistence mechanism installations
  • Enforce encrypted traffic inspection to detect malicious payloads within development tools and coding challenge archives

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image