C
月内に
イランの攻撃グループ「Nimbus Manticore」が、求人サイトを通じてエンジニアを標的にした攻撃を展開しています
📌 一言でいうと
イランの攻撃グループ「Nimbus Manticore」が、求人サイトを通じてエンジニアを標的にした攻撃を展開しています。攻撃者はリクルーターに成りすまし、コーディングテストを装ったアーカイブファイルを送付して、Node.jsやJavaScriptベースのクロスプラットフォームRAT(NodeRabbitおよびPollCat)を感染させます。これにより、WindowsだけでなくLinuxやmacOSシステムも標的となる可能性があります。
🔍該当判定
- LinkedInや求人サイトを通じて、外部から『コーディングテスト(プログラミング試験)』の案内を受けている
- エンジニア採用活動を行っており、候補者に外部サイトでのコーディング試験を依頼している
- 社内でNode.jsやJavaScriptを用いた開発環境を構築・利用している
- LinuxまたはmacOSを搭載したPCを業務で利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
信頼できない送信者から送られてきたコーディングテストや実行ファイルを含むアーカイブを不用意に開かないこと。また、開発環境を分離し、不審なプロセスの動作を監視することを推奨します。
📧 メール案を見る (社員向け + 管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【注意喚起】求人勧誘を装った不正ファイルの送付について
お疲れさまです。情報システム担当です。
リクルーターを装い、コーディングテストなどの「課題ファイル」を送付してウイルスに感染させる攻撃が確認されています。
ご協力をお願いしたいこと:
1. LinkedInなどのSNSやメールで、面識のない人物から送られてきたファイル(特にzip等の圧縮ファイル)を安易にダウンロード・実行しないでください。
2. 不審な連絡を受けた場合は、速やかに情報システム部門へ報告してください。
対応期限: 本日中
お疲れさまです。情報システム担当です。
リクルーターを装い、コーディングテストなどの「課題ファイル」を送付してウイルスに感染させる攻撃が確認されています。
ご協力をお願いしたいこと:
1. LinkedInなどのSNSやメールで、面識のない人物から送られてきたファイル(特にzip等の圧縮ファイル)を安易にダウンロード・実行しないでください。
2. 不審な連絡を受けた場合は、速やかに情報システム部門へ報告してください。
対応期限: 本日中
Subject: [Security Alert] Malicious Files Disguised as Job Recruitment Tests
Dear employees,
We have observed attacks where threat actors pose as recruiters and send malicious files disguised as "coding challenges" or "tests."
Requested Actions:
1. Do not download or execute files (especially compressed archives like .zip) sent by unknown individuals via LinkedIn or email.
2. If you receive any suspicious recruitment messages, please report them to the IT security team immediately.
Deadline: Immediate
Dear employees,
We have observed attacks where threat actors pose as recruiters and send malicious files disguised as "coding challenges" or "tests."
Requested Actions:
1. Do not download or execute files (especially compressed archives like .zip) sent by unknown individuals via LinkedIn or email.
2. If you receive any suspicious recruitment messages, please report them to the IT security team immediately.
Deadline: Immediate
件名: 【共有】Nimbus ManticoreによるクロスプラットフォームRAT感染キャンペーンについて
お疲れさまです。イラン系APTグループ「Nimbus Manticore」による新キャンペーンに関する情報共有です。
■ 概要
Node.jsおよびJavaScriptで開発されたクロスプラットフォームRAT(NodeRabbitおよびPollCat)が、求人プラットフォーム経由の標的型攻撃で使用されています。Windowsに加え、LinuxおよびmacOSも感染対象となるため、開発環境への影響が懸念されます。
■ 影響範囲
- OS: Windows, Linux, macOS
- 対象者: 開発者、エンジニア
■ 対応手順
1. EDR等の監視ツールにて、Node.jsプロセスによる不審な外部通信や、不自然なJavaScriptファイルの実行を監視してください。
2. 開発者が利用するプラットフォーム(LinkedIn等)での不審なファイル受信に関する注意喚起を徹底してください。
■ 参考情報
- Kaspersky Threat Intelligence
対応優先度: 中
対応期限: 随時
お疲れさまです。イラン系APTグループ「Nimbus Manticore」による新キャンペーンに関する情報共有です。
■ 概要
Node.jsおよびJavaScriptで開発されたクロスプラットフォームRAT(NodeRabbitおよびPollCat)が、求人プラットフォーム経由の標的型攻撃で使用されています。Windowsに加え、LinuxおよびmacOSも感染対象となるため、開発環境への影響が懸念されます。
■ 影響範囲
- OS: Windows, Linux, macOS
- 対象者: 開発者、エンジニア
■ 対応手順
1. EDR等の監視ツールにて、Node.jsプロセスによる不審な外部通信や、不自然なJavaScriptファイルの実行を監視してください。
2. 開発者が利用するプラットフォーム(LinkedIn等)での不審なファイル受信に関する注意喚起を徹底してください。
■ 参考情報
- Kaspersky Threat Intelligence
対応優先度: 中
対応期限: 随時
Subject: [Intel] Cross-Platform RAT Campaign by Nimbus Manticore
Dear team,
This is a technical update regarding a campaign by the Iranian APT group Nimbus Manticore.
■ Overview
Attackers are deploying cross-platform RATs named NodeRabbit and PollCat, written in Node.js and obfuscated JavaScript. These are delivered via trojanized coding challenge archives sent through recruitment platforms, targeting Windows, Linux, and macOS systems.
■ Scope
- OS: Windows, Linux, macOS
- Target: Developers and Engineers
■ Mitigation Steps
1. Monitor EDR logs for suspicious Node.js process behavior and unauthorized outbound network connections.
2. Implement strict warnings for developers regarding the execution of untrusted code from external recruitment sources.
■ Reference
- Kaspersky Threat Intelligence
Priority: Medium
Deadline: Ongoing
Dear team,
This is a technical update regarding a campaign by the Iranian APT group Nimbus Manticore.
■ Overview
Attackers are deploying cross-platform RATs named NodeRabbit and PollCat, written in Node.js and obfuscated JavaScript. These are delivered via trojanized coding challenge archives sent through recruitment platforms, targeting Windows, Linux, and macOS systems.
■ Scope
- OS: Windows, Linux, macOS
- Target: Developers and Engineers
■ Mitigation Steps
1. Monitor EDR logs for suspicious Node.js process behavior and unauthorized outbound network connections.
2. Implement strict warnings for developers regarding the execution of untrusted code from external recruitment sources.
■ Reference
- Kaspersky Threat Intelligence
Priority: Medium
Deadline: Ongoing