NodeRabbit and PollCat cross-platform RAT activity
Malware Activity
Summary
Hide ▲
Show ▼
The discovery of NodeRabbit and PollCat adds two previously undocumented cross-platform RATs to Nimbus Manticore's toolset, widening risk across Windows, Linux, and macOS. The malware is delivered through LinkedIn and job-search spear phishing that uses trojanized coding challenge archives, with NodeRabbit first seen in Afghanistan and later on systems in Egypt and Ethiopia. The implants use Azure-hosted C2 and OS-specific persistence while enabling host enumeration, shell execution, and file access.
Related Happenings
Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
Campaign
H score35
First: 01.09.2026 16:08
Last: 01.09.2026 16:08
Sources 1
How related:
"the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage purposes."
About this happening:
Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...
Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign
CampaignHow related: "the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage purposes."
About this happening: Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...
TWINLOOT Microsoft services C2 implant activity
Malware Activity
H score29
First: 18.08.2026 15:38
Last: 18.08.2026 15:38
Sources 1
About this happening:
TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal en...
TWINLOOT Microsoft services C2 implant activity
Malware ActivityAbout this happening: TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal en...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware Activity
H score31
First: 09.07.2026 21:08
Last: 09.07.2026 21:08
Sources 1
About this happening:
The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
GigaWiper / BLUERABBIT destructive Windows backdoor activity
Malware ActivityAbout this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
Campaign
H score37
First: 03.07.2026 16:36
Last: 03.07.2026 16:36
Sources 1
About this happening:
The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors
CampaignAbout this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...
Timeline
-
01.09.2026 16:08 2 articles · 7h ago
Nimbus Manticore linked to NodeRabbit and PollCat cross-platform RATs
Initial DisclosureNimbus Manticore was linked to two previously undocumented cross-platform RATs, NodeRabbit and PollCat, delivered through trojanized coding challenge archives and LinkedIn or other job-search spear phishing. The malware targets Windows, Linux, and macOS, with NodeRabbit first seen on a system in Afghanistan and later recovered from machines in Egypt and Ethiopia; the tooling uses Azure-hosted C2, daily scheduled-task persistence, and command sets for host discovery, shell execution, file access, and other backdoor functions.
Show sources
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests — thehackernews.com — 01.09.2026 16:08
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests — thehackernews.com — 01.09.2026 16:08