Iranian Hackers Use Coding Tests to Deliver Cross-Platform RATs

The Iranian group Nimbus Manticore uses recruiter-themed coding tests to distribute Node.js and JavaScript remote access Trojans on Linux and macOS platforms, as reported by Kaspersky.

Why it matters

This novel tactic demonstrates the evolution of state-sponsored campaigns to target multiple operating systems using socially engineered lures, increasing the complexity of detection and mitigation.

SOC impact

Monitor for unusual activity related to coding test files and Node.js or JavaScript RAT execution on Linux and macOS systems. Validate the presence of recruiter-themed malware lures and review endpoint telemetry for suspicious cross-platform behaviors associated with Nimbus Manticore.

Recommended actions

  1. Identify files resembling recruiter coding tests in network and endpoint logs
  2. Review Node.js and JavaScript execution events on Linux and macOS hosts
  3. Assess organizational exposure to cross-platform RATs linked to Nimbus Manticore
  4. Monitor suspicious inbound interactions originating from recruitment-themed campaigns

Executive Summary

Kaspersky researchers report that the Iranian threat group Nimbus Manticore has expanded its malware toolkit to include novel remote access Trojans specifically targeting Linux and macOS environments. These RATs are delivered through social engineering tactics that mimic recruiter coding tests, capitalizing on the trust placed in legitimate hiring processes. This shift signals an advancement in cross-platform targeting by a state-sponsored actor, complicating detection efforts as attackers leverage Node.js and JavaScript technologies to evade conventional defenses.

For security operations teams, recognizing the intersection of social engineering with cross-platform malware is critical. Monitoring for unexpected coding test files and anomalous scripting activity on non-Windows systems should be prioritized. Understanding these developments aids in contextualizing the evolving threat landscape and tailoring defenses against multifaceted intrusion attempts by sophisticated adversaries like Nimbus Manticore.

SOC Impact

Monitor for unusual activity related to coding test files and Node.js or JavaScript RAT execution on Linux and macOS systems. Validate the presence of recruiter-themed malware lures and review endpoint telemetry for suspicious cross-platform behaviors associated with Nimbus Manticore.

Detection and Exposure Validation

  • Identify files resembling recruiter coding tests in network and endpoint logs
  • Review Node.js and JavaScript execution events on Linux and macOS hosts
  • Assess organizational exposure to cross-platform RATs linked to Nimbus Manticore
  • Monitor suspicious inbound interactions originating from recruitment-themed campaigns

Why It Matters

This novel tactic demonstrates the evolution of state-sponsored campaigns to target multiple operating systems using socially engineered lures, increasing the complexity of detection and mitigation.

Source