Fake Recruiters Lure Devs Into Malware “Coding Tests”

The Record · High sophistication
Last updated September 2, 2026

An Iran-linked espionage group contacted developers and other tech specialists with fake job offers on LinkedIn and similar platforms. Victims were pushed to quickly download and run “coding challenges” that secretly installed new malware, giving attackers remote access and long-term persistence. The campaign focused on aviation/aerospace and financial technology targets in parts of Africa and the Middle East.

How the attack worked

This campaign relied on a fake hiring process to get developers to execute code on their own machines. Recruiters reached out on job-search platforms like LinkedIn with what looked like legitimate tech job offers, then directed candidates toward a coding challenge hosted on cloud storage. Once the developer downloaded and ran the project as instructed, a hidden malicious component executed alongside it. Two malware families, tracked as NodeRabbit and PollCat, were disguised inside these coding challenges and gave attackers remote access and long-term persistence on infected machines.

Why it succeeded

The scheme worked because it mimicked a familiar, low-friction process: technical hiring tests that developers routinely complete as part of interviewing. Attackers layered pressure tactics on top of that trust. Some targets were given only one to three hours to complete a task, and one variation used a single-use six-digit access code valid for only a short window, pushing candidates to open the project quickly rather than review it. One coding test even banned the use of AI assistants, a rule researchers suspect was meant to stop such tools from flagging the hidden malicious code.

What to watch for

  • Unsolicited recruiter contact that quickly pushes you to download and run code
  • A coding assessment delivered as a downloadable archive or project instead of a vetted testing platform
  • Unusual instructions, such as banning AI assistants or other review tools, during a technical test
  • Artificial urgency: short deadlines or "single-use" access codes meant to rush execution
  • Legitimate-looking infrastructure, since the group used Microsoft Azure, Cloudflare, and Amazon cloud storage to blend malicious traffic in with normal activity, in some cases even embedding a target organization's name in an Azure subdomain

How to build resistance

Organizations in software development, aviation, aerospace, and fintech, where this campaign concentrated its targeting, should treat unsolicited recruiter messages as a social-engineering risk rather than routine outreach. Developers should never run unfamiliar coding test files directly on a work or personal machine; instead, any hiring assessment should go through a sandboxed environment or an established, vetted testing platform. Security and recruiting teams should also train staff to recognize urgency-based pressure, such as tight deadlines or single-use codes, as a manipulation tactic rather than a normal part of a hiring process, and to verify recruiter identities through official channels before engaging further.

Key findings

  • Attackers used fake recruiter outreach and job offers to persuade targets to run malicious “programming assignments.”
  • Two malware families were identified (NodeRabbit and PollCat), both disguised as coding challenges in a hiring process.
  • Targets were pressured with short deadlines (one to three hours) and, in one case, a “single-use” six-digit access code.
  • The group used legitimate infrastructure (Microsoft Azure, Cloudflare, and Amazon cloud storage) to blend in and reduce suspicion.

Who’s being targeted

  • Commonly targeted roles: Software Engineers / Developers, Engineering Managers, IT & Security, Recruiting / Talent Acquisition (for verification playbooks), Employees in Aviation, Aerospace, and FinTech.
  • Affected industries: Aviation, Aerospace, Financial technology (FinTech), Software development / Technology specialists.
  • Attack channels: linkedin, website.
  • Impersonated: Recruiter for a major technology company (unnamed), Recruiter running a ‘purported hiring process’, Recruiter providing a time-limited access code.

Red flags to watch for

  • Unsolicited recruiter contact pushing you to run code quickly
  • Assessment delivered as a downloadable archive/project rather than a vetted testing platform
  • Pressure to execute the project immediately
  • Unusual instruction banning AI/security tools or review steps
  • High-pressure deadline designed to reduce careful inspection
  • Coding ‘test’ requires running an unfamiliar project on your workstation
  • Time-limited ‘single-use’ access code intended to rush the target
  • Recruiter insists on opening/running files quickly
  • Nonstandard hiring workflow for code execution on your machine
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers get developers to run malware?

Fake recruiters contacted developers on job platforms with tech job offers and directed them to download a coding challenge hosted on cloud storage, encouraging them to run the project immediately, which secretly executed hidden malicious code alongside it.

What pressure tactics were used in this campaign?

Attackers used short deadlines of one to three hours and, in one case, a single-use six-digit access code valid only for a short time, pushing candidates to open the project quickly instead of reviewing it carefully.

Why did the ban on AI assistants matter?

One coding test explicitly banned the use of AI assistants, which researchers said may have been intended to prevent such tools from detecting the malicious code hidden in the project.

How did the attackers avoid detection?

The group used legitimate Microsoft Azure and Cloudflare infrastructure, and in some cases included the targeted organization's name in an Azure subdomain, making malicious traffic look like normal corporate network activity.

Read the video transcript

You get a LinkedIn message: a great dev role, and they want you to run a quick coding test. Looks legit, right? In a recent campaign, fake recruiters sent ‘coding challenges’ that secretly installed NodeRabbit or PollCat malware when devs ran the project from Amazon cloud storage or Azure links. The hook is pressure: 'Fix this app in three hours.' 'Single-use six-digit code.' 'Do not use AI assistants.' All designed so you run unknown code on your own machine without really checking it. If a recruiter you don’t know wants you to download and run a coding test, stop and send it to security before you ever execute the project.

Similar attacks

Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026