
Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing
The Iranian-linked threat actor Nimbus Manticore has launched a new wave of cross-platform cyber espionage campaigns. By masquerading as recruiters, they are deploying custom RATs to exfiltrate data.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- The Hacker News
- Read Time:
- 4 min
Executive Summary
In late September 2026, threat intelligence researchers identified a significant escalation in cyber espionage activities attributed to the Iranian-nexus group 'Nimbus Manticore.' The group has pivoted its operational focus toward high-value targets in the technology and defense sectors, utilizing a sophisticated social engineering pipeline that leverages fake recruitment drives to deliver malicious payloads.
Threat Analysis
Nimbus Manticore has demonstrated a high degree of operational maturity by integrating their espionage efforts with legitimate-looking professional development workflows. By posing as recruiters from reputable global firms, the actors invite targets to participate in 'technical coding assessments.' These assessments contain embedded malicious scripts designed to bypass standard endpoint detection and response (EDR) solutions, allowing the group to establish persistent access to both Windows and macOS environments.
Technical Details
The primary delivery mechanism involves a multi-stage infection chain. Once a target executes the provided 'coding test' file, a custom-built Remote Access Trojan (RAT) is deployed. This malware, which researchers have dubbed 'Manticore-Shell,' utilizes obfuscated C++ code to communicate with command-and-control (C2) infrastructure disguised as legitimate cloud storage traffic. The malware is capable of keylogging, screen capturing, and the exfiltration of sensitive environment variables, which the group uses to pivot into internal corporate networks.
Attribution Assessment
Based on the TTPs (Tactics, Techniques, and Procedures) observed—specifically the use of custom cross-platform RATs and the specific targeting of overseas dissidents and technology professionals—analysts have high confidence in attributing this campaign to Nimbus Manticore. The group’s infrastructure overlaps with previous campaigns targeting South Korean electronics manufacturers and Middle Eastern government entities, suggesting a centralized state-sponsored mandate.
Implications
This campaign highlights a critical vulnerability in the modern 'remote-first' hiring process. By exploiting the trust inherent in technical interviews, Nimbus Manticore has successfully bypassed traditional perimeter defenses. The exfiltration of proprietary source code and internal communications poses a severe risk to the intellectual property of the targeted organizations and potentially compromises the security of downstream supply chains.
Recommendations
Organizations are advised to implement strict sandboxing protocols for all incoming files, including those received from 'recruiters' or external partners. Security teams should monitor for anomalous outbound traffic to unknown cloud storage providers and enforce multi-factor authentication (MFA) on all developer workstations. Furthermore, conducting regular threat hunting exercises focused on identifying unauthorized persistence mechanisms on macOS and Linux systems is essential to mitigating the impact of this evolving threat.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Iranian Espionage Campaign Deploys 'CHOSEN BRICK' Trojan Against Nationals Abroad

China-Linked Jewelbug Group Escalates Espionage and Crypto Fraud Across Middle East and Asia

