News Room
16
Share
Iranian APT Nimbus Manticore Deploys Cross-Platform 'NodeRabbit' and 'PollCat' RATs via Deceptive Coding Tests
highThreat Intelligence

Iranian APT Nimbus Manticore Deploys Cross-Platform 'NodeRabbit' and 'PollCat' RATs via Deceptive Coding Tests

Iranian threat actor Nimbus Manticore is targeting developers with new Node.js-based malware families, NodeRabbit and PollCat, delivered through fraudulent recruitment campaigns and coding assessments.

03 September 2026Last updated 03 September 20265 min readKaspersky
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
APT
Geography:
Middle East and Africa
Confidence:
High Confidence
Source:
Kaspersky
Read Time:
5 min

Executive Summary\nRecent intelligence from Kaspersky and The Hacker News identifies a significant escalation in the operations of Nimbus Manticore (also known as Mirage Kitten, UNC1549, or Smoke Sandstorm). The group has introduced two previously undocumented malware families, NodeRabbit and PollCat, designed to compromise Linux and macOS systems. This shift marks a strategic expansion from their traditional Windows-centric toolset, utilizing cross-platform frameworks like Node.js to maintain persistence across diverse enterprise environments. The campaign specifically targets the aviation and fintech sectors, focusing on high-value personnel with technical access to sensitive infrastructure.\n\n## Threat Analysis\nThe campaign leverages highly targeted social engineering, specifically posing as recruiters for high-tech firms. Attackers approach developers on professional networking platforms, inviting them to complete "coding tests" or "technical assessments." These assessments contain malicious files that, when executed, deploy the initial stage of the infection chain. This tactic exploits the inherent trust in recruitment processes and the common practice of developers running untrusted code in local environments. By masquerading as a legitimate career opportunity, the threat actor bypasses traditional perimeter defenses that focus on malicious attachments or links. The use of cross-platform RATs ensures that the actor can maintain a foothold regardless of the developer's operating system, which is often macOS or Linux in modern cloud-native development environments.\n\n## Technical Details\nNodeRabbit is a sophisticated Remote Access Trojan (RAT) developed in Node.js. It facilitates command execution, file exfiltration, and further payload delivery. PollCat serves as a secondary backdoor, primarily focused on maintaining a persistent connection to the actor's command-and-control (C2) infrastructure. By using JavaScript and Node.js, the actors achieve high portability across operating systems while blending in with legitimate developer tools and processes. Analysis shows the malware utilizes encrypted communication channels to evade standard network monitoring. The malware also includes modules for environment fingerprinting, allowing the actor to tailor subsequent stages of the attack based on the victim's specific configuration. The C2 infrastructure often utilizes legitimate-looking domains to blend in with standard cloud service traffic, making detection through DNS filtering more difficult.\n\n## Attribution Assessment\nResearchers attribute this activity to Nimbus Manticore with high confidence. The group is widely believed to be affiliated with the Iranian Islamic Revolutionary Guard Corps (IRGC). The TTPs (Tactics, Techniques, and Procedures) align with previous Mirage Kitten operations, including the focus on aviation, defense, and fintech sectors in the Middle East and Africa. The evolution to cross-platform tools suggests a maturing capability aimed at bypassing Windows-specific security controls and targeting the growing population of developers using macOS and Linux for cloud-native development. This aligns with broader Iranian strategic interests in gathering intelligence from critical infrastructure and financial sectors.\n\n## Implications\nThe emergence of NodeRabbit and PollCat highlights a growing trend among state-sponsored actors to target non-Windows assets, which are often less rigorously monitored in corporate environments. The use of developer-focused social engineering indicates a shift toward high-value targets who possess privileged access to source code and internal infrastructure. This campaign demonstrates that even highly technical users are vulnerable to sophisticated social engineering when it is integrated into standard professional workflows like recruitment. The ability to compromise developer machines provides a potential gateway for supply-chain attacks or deep lateral movement within corporate networks.\n\n## Recommendations\nOrganizations should implement strict vetting for recruitment-related software and encourage developers to run assessments in isolated sandbox environments. Enhanced monitoring for unauthorized Node.js processes and unusual outbound traffic to known C2 patterns is critical. EDR solutions should be configured to detect the specific behavioral signatures of NodeRabbit's execution chain, such as unexpected use of the child_process or fs modules in Node.js. Furthermore, security awareness training should specifically address the risks of "technical assessments" from unverified sources. Organizations should also consider implementing zero-trust principles for developer workstations to limit the impact of a potential compromise.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo