Iranian Hackers Nimbus Manticore Target Mac and Linux With Fake Job Tests

Kaspersky says the state-linked crew is now posing as recruiters and hiding remote-access malware inside coding challenges sent to job hunters.

ThreatVectr Newsdesk· 3 min read
Full-frame overhead view of a modern silver laptop on a dark wooden desk, screen showing a blurred generic system password dialog with a red warning glow, apps
Share

Key points

  • Kaspersky has tied Iranian hacking group Nimbus Manticore to two new pieces of malware built to run on Windows, Mac and Linux computers.
  • The attackers pose as recruiters and send fake coding tests to job seekers, which quietly install the spy tools when opened.
  • The malware is written in Node.js and JavaScript, common web-developer languages, so a single version works across all three operating systems.
  • Targets appear to include people working in aerospace, defence and telecoms, sectors Iranian crews have hit before.
  • No ransom is involved. The goal is spying, not extortion.

Iranian hacking crew Nimbus Manticore has quietly expanded its arsenal, and its list of possible victims, with two new pieces of malware that can spy on Windows, Mac and Linux machines alike.

The finding comes from Russian antivirus firm Kaspersky, which tracks the group and published its analysis this week. The Hacker News first flagged the report.

Nimbus Manticore is a state-aligned Iranian outfit that security researchers have watched for several years. It is not a ransomware gang. It steals information, usually from companies in aerospace, defence, and telecoms, the kind of targets Tehran's intelligence services care about.

How does the attack actually work?

The hackers pretend to be recruiters. They approach people on job sites and messaging apps, strike up a friendly conversation about a role, then send over a "coding test" the candidate has to complete. Opening the file installs the malware.

Once the file is run, it plants a remote access trojan, a piece of malicious software that lets an outside operator quietly control the computer. From there the attackers can read files, watch what the user types, and pivot into the victim's employer.

The fake-recruiter trick is not new. North Korean crews have used it for years against cryptocurrency engineers. What is new here is the polish, and the fact that Iran's operators are now using it too.

Why does the Mac and Linux angle matter?

Most commodity spyware only runs on Windows, because Windows still dominates corporate desktops. By writing the new tools in Node.js and JavaScript, two languages used to build websites, Nimbus Manticore gets one codebase that runs on all three major operating systems with little extra work.

That matters because engineers, researchers and journalists, the people this group tends to target, disproportionately use Macs and Linux laptops. Until now, many of them assumed their choice of computer gave them some protection from Iranian spying. It no longer does.

What we know so far

Detail What Kaspersky reported
Group Nimbus Manticore (Iran-linked)
New malware Two cross-platform remote access trojans
Built with Node.js and JavaScript
Systems hit Windows, macOS, Linux
Delivery Fake recruiter messages with coding tests
Likely targets Aerospace, defence, telecoms staff

Kaspersky has not named specific victim companies, and no ransom demands are attached to this activity. The operation looks purely about intelligence gathering.

What should ordinary readers do?

If you are job hunting, treat unsolicited recruiter messages with the same suspicion as an unexpected email from your bank. Real recruiters almost never ask you to run a downloaded file on your own computer. A legitimate coding test lives inside a browser on a known platform like HackerRank or Codility.

A few plain rules help:

  1. Verify the recruiter on the hiring company's own website before opening anything.
  2. Run any test file inside a throwaway virtual machine, or ask to complete the task in the browser.
  3. If a "recruiter" pushes you to hurry, stop. Urgency is the tell.
  4. Keep your operating system and antivirus updated, even on a Mac or Linux laptop.

For employers, the takeaway is blunter. Staff on LinkedIn are now a delivery channel for state-level spyware, and the malware no longer cares what laptop they use.

© 2026 Threat Vectr