The Iranian hacking group Nimbus Manticore has been linked to two new malware families that significantly enhance its capabilities by enabling cross-platform attacks against Linux and Apple macOS systems. Utilizing remote access trojans (RATs) crafted with Node.js and JavaScript, the group employs a novel approach by posing as recruiters to deliver these malicious tools under the guise of coding tests. This tactic not only broadens their operational scope but also illustrates a sophisticated evolution in their methodology, raising concerns about the potential for wider exploitation of unsuspecting users in the tech industry.
For businesses, particularly those operating in environments that include Linux and macOS systems, this development underscores the necessity for comprehensive cybersecurity measures that extend beyond traditional defenses. The use of social engineering tactics, such as recruitment attempts, highlights the importance of employee training and awareness programs to recognize and mitigate phishing attempts and other deceptive practices. As cyber threats continue to evolve, organizations must prioritize robust security protocols and proactive threat monitoring to defend against these increasingly complex attacks, making this a critical moment for reevaluating cybersecurity strategies across the board.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html)*