Iranian state-sponsored group Nimbus Manticore has deployed two previously unknown remote access trojans targeting Windows, Linux, and macOS systems through a social engineering campaign impersonating tech recruiters, according to Kaspersky research.
The group lures software developers into downloading malicious coding test files disguised as legitimate job screening materials. Once executed, the trojans establish persistent remote access to infected systems across multiple platforms. Both RAT families are built using Node.js and JavaScript, enabling Nimbus Manticore to maintain a single codebase while attacking diverse operating systems.
This represents a significant expansion of the group's traditional targeting scope. Nimbus Manticore, designated by the U.S. as an Iranian Islamic Revolutionary Guard Corps affiliate, previously focused predominantly on Windows-based targets. The new cross-platform tooling allows the group to compromise developers and engineers regardless of their preferred operating system.
The attack chain begins with recruitment-themed social engineering. Nimbus Manticore operators, posing as hiring managers or technical recruiters, contact potential targets through LinkedIn and other professional networks. They direct victims to complete coding assessments or technical evaluations. The provided test files contain obfuscated JavaScript and Node.js payloads that execute silently during what victims believe is a legitimate coding challenge.
Once installed, the RATs establish command-and-control communication allowing operators to execute arbitrary commands, harvest credentials, exfiltrate files, and maintain persistence across system reboots. The use of JavaScript and Node.js demonstrates the group's modernization efforts. These technologies require no platform-specific compilation, reducing detection signatures and simplifying deployment across Windows, Linux, and macOS environments.
The targeting of software developers carries specific operational value for Iranian intelligence services. Developers typically maintain elevated access to corporate networks, source code repositories, and sensitive development environments. A single compromised developer account can provide gateway access to entire organizations. This explains why Nimbus Manticore invests in social engineering campaigns specifically designed to appeal to technical professionals through job-related pretexts.
Kaspersky's attribution to Nimbus Manticore relies on infrastructure overlaps, command-and-control server patterns, and behavioral indicators consistent with previous group campaigns. The research identifies specific malware families but does not name the trojans in publicly available summaries. Researchers are tracking the threat group's ongoing capability development and recommend immediate investigation for any organizations experiencing suspicious recruitment-themed contact with employees claiming to involve coding assessments.
Organizations should implement security awareness training emphasizing verification of recruiter legitimacy through official company channels before downloading any assessment materials. Endpoint detection and response tools should monitor for Node.js process execution in atypical contexts and JavaScript deobfuscation attempts. Network monitoring should flag outbound connections to newly registered or suspicious domains from developer workstations.
The discovery underscores how state-sponsored groups continuously adapt tactics to expand their victim pool and operational capabilities. The shift toward cross-platform malware reflects the heterogeneous environments modern development teams operate within. Organizations employing developers face heightened targeting risk and must implement both technical controls and human-centered security practices to defend against sophisticated social engineering campaigns leveraging professional contexts.
