HackerFeeds

CyberSecurity News

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News
· September 1, 2026

AI summary

Iranian hacking group Nimbus Manticore has been linked to two new malware families that demonstrate an expansion of its capabilities. These malware families are cross-platform remote access trojans developed using Node.js and JavaScript, allowing them to infect Linux and Apple macOS systems. The group's tactics involve posing as recruiters who send coding tests to targets, which deliver the malware. Kaspersky, a Russian cybersecurity company, is monitoring the activities of this group. The new malware families indicate the group's evolving toolset and potentially broader targeting scope.

Read the full article at The Hacker Newsthehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.