{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/recruitment/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":["Nimbus Manticore"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VS Code","Outlook"],"_cs_severities":["high"],"_cs_tags":["espionage","rat","phishing","recruitment","cross-platform"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThe Iranian threat actor Nimbus Manticore (also known as Iranian Dream Job) has expanded its arsenal with two new Node.js-based remote access trojans (RATs), NodeRabbit and PollCat. These tools are delivered via spear-phishing campaigns on platforms like LinkedIn, where attackers pose as recruiters. Victims are lured into downloading trojanized coding challenge archives containing a project management application. Malicious code is embedded within the project's 'server.js' file, which imports a trojanized npm package ('colorized_terminal' or 'pretty-log') to silently launch an implant. These RATs are cross-platform, affecting Windows, Linux, and macOS, and are used for cyber espionage. The group has historically used C, C++, and Go, but the shift to Node.js indicates an effort to blend into developer environments and simplify cross-platform deployment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes contact with a software engineer on LinkedIn, posing as a talent acquisition specialist.\u003c/li\u003e\n\u003cli\u003eVictim downloads a ZIP archive (e.g., 'Front-Technical-Challenge.zip') containing a project management tool.\u003c/li\u003e\n\u003cli\u003eVictim runs the 'server.js' component, which triggers the import of a trojanized npm package ('colorized_terminal' or 'pretty-log').\u003c/li\u003e\n\u003cli\u003eThe malicious package executes an index.js file from 'node_modules/.cache/' as a detached background process.\u003c/li\u003e\n\u003cli\u003eThe NodeRabbit/PollCat implant establishes C2 communication with Azure-hosted infrastructure via hardcoded API endpoints.\u003c/li\u003e\n\u003cli\u003eMalware ensures persistence using OS-specific methods (Windows Registry Run keys, Linux cron jobs, or macOS launch agents).\u003c/li\u003e\n\u003cli\u003eAttacker executes commands to harvest system data, steal browser/Outlook credentials, or inject persistence mechanisms into local Git repositories.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign targets software engineers in critical sectors across the Middle East and Africa. Successful exploitation allows for complete remote control of the host, enabling data exfiltration, credential harvesting (including Outlook OST/PST files), and deep reconnaissance of the victim's development environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eBlock the C2 domains listed in the IOC table at the DNS resolver level to disrupt command-and-control communications.\u003c/li\u003e\n\u003cli\u003eImplement detection logic to monitor for unexpected npm package imports from non-registry locations or obscure paths within project 'node_modules' directories.\u003c/li\u003e\n\u003cli\u003eProhibit the execution of untrusted coding challenges on systems with access to production environments or sensitive source code.\u003c/li\u003e\n\u003cli\u003eHunt for the presence of the identified malicious npm package names ('colorized_terminal' v2.1.0, 'pretty-log' v2.1.0) in local node_modules folders.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T14:10:08Z","date_published":"2026-09-01T14:10:08Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nimbus-manticore-recruitment/","summary":"The Iranian threat actor Nimbus Manticore is distributing NodeRabbit and PollCat cross-platform RATs via trojanized coding challenges on LinkedIn to compromise developer systems.","title":"Nimbus Manticore Targets Developers with Node.js-based Cross-Platform RATs","url":"https://feed.craftedsignal.io/briefs/2026-09-nimbus-manticore-recruitment/"}],"language":"en","title":"CraftedSignal Threat Feed - Recruitment","version":"https://jsonfeed.org/version/1.1"}