started · updated
Iran-linked hackers use fake coding tests to spread malware
Cybersecurity researchers at Kaspersky have identified a new tactic used by Iran-linked threat actors, specifically the groups Mirage Kitten and Nimbus Manticore, to distribute malware through fake job recruitment processes.
According to the research, attackers masquerade as recruiters on platforms like LinkedIn to target software engineers. They provide coding assessments hosted on legitimate-looking Amazon S3 links. These archives contain trojanized code designed to infect systems via two previously undocumented malware families: NodeRabbit and PollCat.
A notable aspect of this campaign is the use of social engineering to bypass modern security tools. The coding challenges include instructions prohibiting the use of AI assistants. Researchers noted that this rule is likely intended to prevent AI-driven code-review tools from detecting the suspicious imports and malicious code within the project.
While the group has historically used languages like C and C++, these new cross-platform remote access trojans (RATs) are developed using Node.js and JavaScript, allowing them to target Linux and macOS systems. Initial sightings of the malware have been documented in Afghanistan, Egypt, and Ethiopia.
Entities
Amazon · Kaspersky · LinkedIn · Mirage Kitten · Nimbus Manticore