Iranian Hacking Group Targets Tech Workers in Africa and Middle East via Job Scams
AI-generated from multiple sources. Verify before acting on this reporting.
TEHRAN — An Iranian cyberespionage group known as Nimbus Manticore, also referred to as Iranian Dream Job, launched a sophisticated campaign on Sept. 1, 2026, targeting technology professionals across Afghanistan, Egypt, and Ethiopia. The operation utilized deceptive recruitment tactics to distribute cross-platform remote access trojans (RATs) designed to compromise Linux and Apple macOS systems.
The group posed as legitimate recruiters, reaching out to potential victims through professional networking sites and job boards. Instead of standard interview requests, the actors distributed malicious archives disguised as coding challenges. These files were engineered to appear as legitimate technical assessments for software engineering roles. Once downloaded and executed by the target, the malware established a persistent backdoor on the victim's machine, granting attackers full remote control.
Security analysis indicates the trojans were developed using Node.js and JavaScript frameworks, allowing them to function seamlessly across different operating systems without requiring separate payloads for each environment. This cross-platform capability significantly expanded the group's reach, enabling a single malicious file to infect both Unix-based Linux servers and macOS workstations commonly used by developers in the targeted regions.
The campaign specifically focused on individuals with access to sensitive corporate networks or government infrastructure within Afghanistan, Egypt, and Ethiopia. By embedding the malware within what appeared to be routine career advancement opportunities, the attackers bypassed traditional security filters that might flag unsolicited emails or suspicious links. The use of professional recruitment channels provided a layer of credibility that likely increased the success rate of the infection attempts.
Nimbus Manticore has previously been linked to state-sponsored cyber operations aimed at gathering intelligence on diplomatic and technological sectors. This latest activity marks a shift toward targeting individual high-value users rather than broad network sweeps, suggesting a more granular approach to data exfiltration. The malware's architecture allows for long-term persistence, potentially enabling the group to monitor communications, steal credentials, and move laterally within victim networks over extended periods.
As of late Tuesday, the full extent of the compromise remains unclear. It is not yet known how many individuals successfully downloaded the malicious archives or whether any data has already been exfiltrated from the infected systems. Cybersecurity experts are currently working to identify the specific variants of the trojan in circulation and develop signatures to detect future iterations of the campaign.
The incident raises concerns about the vulnerability of professional networking platforms to state-sponsored actors. As remote work and digital hiring continue to expand, the line between legitimate recruitment and cyberespionage becomes increasingly blurred. Authorities in the affected nations have not yet issued public statements regarding the breach or confirmed any specific impacts on national infrastructure. Investigations into the scope of the attack are ongoing.