Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
Campaign
Summary
Hide ▲
Show ▼
Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation is aimed at critical sectors across the Middle East and Africa and is built for cyber espionage, not one-off theft. Its cross-platform payloads, including NodeRabbit and PollCat, increase risk for Windows, Linux, and macOS developer systems.
Related Happenings
NodeRabbit and PollCat cross-platform RAT activity
Malware Activity
H score22
First: 01.09.2026 16:08
Last: 01.09.2026 16:08
Sources 1
How related:
"Its operators deliver [NodeRabbit] through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives,"
About this happening:
The discovery of NodeRabbit and PollCat adds two previously undocumented cross-platform RATs to Nimbus Manticore's toolset, widening risk across Windows, Lin...
NodeRabbit and PollCat cross-platform RAT activity
Malware ActivityHow related: "Its operators deliver [NodeRabbit] through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives,"
About this happening: The discovery of NodeRabbit and PollCat adds two previously undocumented cross-platform RATs to Nimbus Manticore's toolset, widening risk across Windows, Lin...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor Meta
H score62
First: 14.08.2026 10:30
Last: 14.08.2026 10:30
Sources 1
About this happening:
Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...
Roblox fake Xeno Executor installer campaign
Campaign
H score36
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
Roblox fake Xeno Executor installer campaign
CampaignAbout this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
Timeline
-
01.09.2026 16:08 2 articles · 7h ago
Nimbus Manticore delivers NodeRabbit and PollCat through recruiter lures
Initial DisclosureNimbus Manticore, also tracked as Iranian Dream Job, used LinkedIn and other job-search platforms to send spear-phishing messages that pointed technical targets to trojanized coding challenge archives. The archives bundled the cross-platform RATs NodeRabbit and PollCat, expanded the group's toolset to Windows, Linux, and macOS, and were linked to sightings on systems in Afghanistan, Egypt, and Ethiopia.
Show sources
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests — thehackernews.com — 01.09.2026 16:08
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests — thehackernews.com — 01.09.2026 16:08