Iranian Hackers Exploit Recruitment Scams to Deploy Cross-Platform RATs via Coding Challenges
Iranian hackers are using recruitment-themed phishing attacks to deliver cross-platform Remote Access Trojans (RATs) through coding challenges, leveraging Node.js and JavaScript to target Linux and macOS systems. The malware, named NodeRabbit and PollCat, employs obfuscated code and persistence mechanisms to maintain access and exfiltrate data via Azure-hosted command-and-control servers.
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.
Russian cybersecurity company Kaspersky is tracking the
*** END OF TRANSMISSION ***