News Room
16
Share
Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing
highCyber Espionage

Iranian 'Nimbus Manticore' APT Escalates Global Espionage via Sophisticated Coding Test Phishing

The Iranian-linked threat actor Nimbus Manticore has launched a new wave of cross-platform cyber espionage campaigns. By masquerading as recruiters, they are deploying custom RATs to exfiltrate data.

30 September 2026Last updated 30 September 20264 min readThe Hacker News
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Cyber Espionage
Severity:
High
Actor Type:
Nation-State
Geography:
Global
Confidence:
High Confidence
Source:
The Hacker News
Read Time:
4 min

Executive Summary

In late September 2026, threat intelligence researchers identified a significant escalation in cyber espionage activities attributed to the Iranian-nexus group 'Nimbus Manticore.' The group has pivoted its operational focus toward high-value targets in the technology and defense sectors, utilizing a sophisticated social engineering pipeline that leverages fake recruitment drives to deliver malicious payloads.

Threat Analysis

Nimbus Manticore has demonstrated a high degree of operational maturity by integrating their espionage efforts with legitimate-looking professional development workflows. By posing as recruiters from reputable global firms, the actors invite targets to participate in 'technical coding assessments.' These assessments contain embedded malicious scripts designed to bypass standard endpoint detection and response (EDR) solutions, allowing the group to establish persistent access to both Windows and macOS environments.

Technical Details

The primary delivery mechanism involves a multi-stage infection chain. Once a target executes the provided 'coding test' file, a custom-built Remote Access Trojan (RAT) is deployed. This malware, which researchers have dubbed 'Manticore-Shell,' utilizes obfuscated C++ code to communicate with command-and-control (C2) infrastructure disguised as legitimate cloud storage traffic. The malware is capable of keylogging, screen capturing, and the exfiltration of sensitive environment variables, which the group uses to pivot into internal corporate networks.

Attribution Assessment

Based on the TTPs (Tactics, Techniques, and Procedures) observed—specifically the use of custom cross-platform RATs and the specific targeting of overseas dissidents and technology professionals—analysts have high confidence in attributing this campaign to Nimbus Manticore. The group’s infrastructure overlaps with previous campaigns targeting South Korean electronics manufacturers and Middle Eastern government entities, suggesting a centralized state-sponsored mandate.

Implications

This campaign highlights a critical vulnerability in the modern 'remote-first' hiring process. By exploiting the trust inherent in technical interviews, Nimbus Manticore has successfully bypassed traditional perimeter defenses. The exfiltration of proprietary source code and internal communications poses a severe risk to the intellectual property of the targeted organizations and potentially compromises the security of downstream supply chains.

Recommendations

Organizations are advised to implement strict sandboxing protocols for all incoming files, including those received from 'recruiters' or external partners. Security teams should monitor for anomalous outbound traffic to unknown cloud storage providers and enforce multi-factor authentication (MFA) on all developer workstations. Furthermore, conducting regular threat hunting exercises focused on identifying unauthorized persistence mechanisms on macOS and Linux systems is essential to mitigating the impact of this evolving threat.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo