Find notable cyber news and cases, enriched with sources, timelines, and signals.

NodeRabbit and PollCat cross-platform RAT activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The discovery of NodeRabbit and PollCat adds two previously undocumented cross-platform RATs to Nimbus Manticore's toolset, widening risk across Windows, Linux, and macOS. The malware is delivered through LinkedIn and job-search spear phishing that uses trojanized coding challenge archives, with NodeRabbit first seen in Afghanistan and later on systems in Egypt and Ethiopia. The implants use Azure-hosted C2 and OS-specific persistence while enabling host enumeration, shell execution, and file access.

Related Happenings

Nimbus Manticore LinkedIn recruiter-persona cyber espionage campaign

Campaign
H score35 First: 01.09.2026 16:08 Last: 01.09.2026 16:08 Sources 1

How related: "the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage purposes."

About this happening: Nimbus Manticore has expanded a LinkedIn recruiter-persona campaign that uses trojanized coding challenge archives to deliver malware to technical targets. The operation i...

TWINLOOT Microsoft services C2 implant activity

Malware Activity
H score29 First: 18.08.2026 15:38 Last: 18.08.2026 15:38 Sources 1

About this happening: TWINLOOT is a newly disclosed Python implant that hides command-and-control inside Microsoft services, increasing the odds that malicious traffic blends into normal en...

AmnesiaStealer macOS infostealer distributed via ClickFix

Malware Activity
H score16 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...

GigaWiper / BLUERABBIT destructive Windows backdoor activity

Malware Activity
H score31 First: 09.07.2026 21:08 Last: 09.07.2026 21:08 Sources 1

About this happening: The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that on...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

Timeline

  1. 01.09.2026 16:08 2 articles · 7h ago

    Nimbus Manticore linked to NodeRabbit and PollCat cross-platform RATs

    Initial Disclosure

    Nimbus Manticore was linked to two previously undocumented cross-platform RATs, NodeRabbit and PollCat, delivered through trojanized coding challenge archives and LinkedIn or other job-search spear phishing. The malware targets Windows, Linux, and macOS, with NodeRabbit first seen on a system in Afghanistan and later recovered from machines in Egypt and Ethiopia; the tooling uses Azure-hosted C2, daily scheduled-task persistence, and command sets for host discovery, shell execution, file access, and other backdoor functions.

    Show sources