Fake job interview

Hackers Spread Malware via Fake Coding Tests

Hacker Hände
Facebook
X
LinkedIn
Reddit
WhatsApp

According to a Kaspersky analysis, the Iranian hacker group Nimbus Manticore is deploying two previously unknown malware families named NodeRabbit and PollCat.

In doing so, the attackers pose as recruiters from major technology companies to software developers and invite target individuals via LinkedIn and other job platforms to an alleged technical assignment. In the documented case, such an assignment contained the source code of a fictional project management tool along with instructions to fix all bugs in the frontend code within three hours, explicitly without using AI-supported tools. The server component, which was explicitly described as allegedly bug-free and therefore excluded from modification, contained the injected malicious code. Via a manipulated package delivered directly within the task archive rather than through the regular npm directory, this silently downloaded the actual NodeRabbit malware in the background.

Ad

NodeRabbit subsequently communicates with one of three Azure-hosted control servers and supports a total of eleven commands, including reading system information, executing arbitrary shell commands, reading and writing files, and capturing network settings. Kaspersky found two additional variants of the same malware in Egypt and Ethiopia, one of them with a total of 12 additional commands, including the targeted extraction of account data from Outlook mailbox files as well as the installation of a fake Visual Studio Code extension disguised as “GitHub Copilot Helper” for additional stealth and persistence.

Second hacker malware exploits time pressure via one-time code

A second documented campaign spreads the PollCat malware via similarly structured, time-limited coding tasks. Notable here: The actual project, allegedly disguised as a competition platform, consistently contains terms from the field of classic hacking competitions, even though the actual task has nothing to do with it—in Kaspersky’s assessment, a possible indication that the attackers had the basic structure generated using an AI coding assistant and only subsequently inserted the malicious code.

An attached PDF tutorial also instructs target individuals to enter a six-digit one-time code that expires every 30 seconds and to complete the task within one hour, a procedure that Kaspersky says is specifically intended to create artificial time pressure. PollCat itself already continues running in the background independently of this confirmation process and supports 22 commands for file access, command execution, and uploading and downloading files. Additionally, the malware specifically searches the system for folders of 24 well-known security and software vendors, including Kaspersky itself, Microsoft, Cisco, and CrowdStrike. Kaspersky researcher Omar Amin contextualized the technical evolution as follows:

Ad

“The transition to cross-platform scripting languages provides the operators with a single, shared codebase.”

Omar Amin, Kaspersky Researcher

This runs equally under Windows, Linux, and macOS, allowing it to be unobtrusively embedded into conventional developer environments, while the actual distribution method via fake recruiter profiles on LinkedIn continues to match the group’s long-known procedure for targeting critical sectors in the Middle East and Africa for cyber espionage purposes.

(Editorial Team)

Ad

Weitere Artikel