Find notable cyber news and cases, enriched with sources, timelines, and signals.

Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation is aimed at critical sectors across the Middle East and Africa and is built for cyber espionage, not one-off theft. Its cross-platform payloads, including NodeRabbit and PollCat, increase risk for Windows, Linux, and macOS developer systems.

Related Happenings

NodeRabbit and PollCat cross-platform RAT activity

Malware Activity
H score22 First: 01.09.2026 16:08 Last: 01.09.2026 16:08 Sources 1

How related: "Its operators deliver [NodeRabbit] through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives,"

About this happening: The discovery of NodeRabbit and PollCat adds two previously undocumented cross-platform RATs to Nimbus Manticore's toolset, widening risk across Windows, Lin...

Jewelbug's shared-infrastructure hack-for-hire model links espionage and crypto fraud

Threat Actor Meta
H score62 First: 14.08.2026 10:30 Last: 14.08.2026 10:30 Sources 1

About this happening: Jewelbug is a China-linked hack-for-hire threat actor using shared XG-Web infrastructure to run espionage and cryptocurrency fraud in parallel. Broadcom’s Sy...

Roblox fake Xeno Executor installer campaign

Campaign
H score36 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

About this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

Timeline

  1. 01.09.2026 16:08 2 articles · 7h ago

    Nimbus Manticore delivers NodeRabbit and PollCat through recruiter lures

    Initial Disclosure

    Nimbus Manticore, also tracked as Iranian Dream Job, used LinkedIn and other job-search platforms to send spear-phishing messages that pointed technical targets to trojanized coding challenge archives. The archives bundled the cross-platform RATs NodeRabbit and PollCat, expanded the group's toolset to Windows, Linux, and macOS, and were linked to sightings on systems in Afghanistan, Egypt, and Ethiopia.

    Show sources