Fake Job Interviews, Real Malware: Iranian Hackers Target Windows, Mac and Linux Users
Security researchers at Kaspersky have identified two new malware families linked to the Iranian hacking group Nimbus Manticore, showing the group is expanding its capabilities to target Windows, Linux and macOS systems. The attackers pose as recruiters, luring victims with fake job opportunities and coding tests, then use these interactions to deliver remote access trojans (RATs) built with Node.js and JavaScript.
Because the malware is cross-platform, it can infect a wider range of devices than traditional Windows-only tools, giving attackers remote control over compromised machines regardless of operating system. This recruitment-themed social engineering tactic is particularly effective because it exploits trust in professional hiring processes, making victims more likely to download and run unfamiliar files without suspicion.
While this campaign has been linked to state-sponsored espionage activity, the techniques used—fake job offers, coding assessments, and disguised malicious attachments—are increasingly common across cybercrime more broadly. Small businesses, especially those with remote hiring processes or freelance developers, should be aware that job-related communications can be weaponised to deliver malware.