An Iran-linked espionage group contacted developers and other tech specialists with fake job offers on LinkedIn and similar platforms. Victims were pushed to quickly download and run “coding challenges” that secretly installed new malware, giving attackers remote access and long-term persistence. The campaign focused on aviation/aerospace and financial technology targets in parts of Africa and the Middle East.
How the attack worked
This campaign relied on a fake hiring process to get developers to execute code on their own machines. Recruiters reached out on job-search platforms like LinkedIn with what looked like legitimate tech job offers, then directed candidates toward a coding challenge hosted on cloud storage. Once the developer downloaded and ran the project as instructed, a hidden malicious component executed alongside it. Two malware families, tracked as NodeRabbit and PollCat, were disguised inside these coding challenges and gave attackers remote access and long-term persistence on infected machines.
Why it succeeded
The scheme worked because it mimicked a familiar, low-friction process: technical hiring tests that developers routinely complete as part of interviewing. Attackers layered pressure tactics on top of that trust. Some targets were given only one to three hours to complete a task, and one variation used a single-use six-digit access code valid for only a short window, pushing candidates to open the project quickly rather than review it. One coding test even banned the use of AI assistants, a rule researchers suspect was meant to stop such tools from flagging the hidden malicious code.
What to watch for
- Unsolicited recruiter contact that quickly pushes you to download and run code
- A coding assessment delivered as a downloadable archive or project instead of a vetted testing platform
- Unusual instructions, such as banning AI assistants or other review tools, during a technical test
- Artificial urgency: short deadlines or "single-use" access codes meant to rush execution
- Legitimate-looking infrastructure, since the group used Microsoft Azure, Cloudflare, and Amazon cloud storage to blend malicious traffic in with normal activity, in some cases even embedding a target organization's name in an Azure subdomain
How to build resistance
Organizations in software development, aviation, aerospace, and fintech, where this campaign concentrated its targeting, should treat unsolicited recruiter messages as a social-engineering risk rather than routine outreach. Developers should never run unfamiliar coding test files directly on a work or personal machine; instead, any hiring assessment should go through a sandboxed environment or an established, vetted testing platform. Security and recruiting teams should also train staff to recognize urgency-based pressure, such as tight deadlines or single-use codes, as a manipulation tactic rather than a normal part of a hiring process, and to verify recruiter identities through official channels before engaging further.
Key findings
- Attackers used fake recruiter outreach and job offers to persuade targets to run malicious “programming assignments.”
- Two malware families were identified (NodeRabbit and PollCat), both disguised as coding challenges in a hiring process.
- Targets were pressured with short deadlines (one to three hours) and, in one case, a “single-use” six-digit access code.
- The group used legitimate infrastructure (Microsoft Azure, Cloudflare, and Amazon cloud storage) to blend in and reduce suspicion.
Who’s being targeted
- Commonly targeted roles: Software Engineers / Developers, Engineering Managers, IT & Security, Recruiting / Talent Acquisition (for verification playbooks), Employees in Aviation, Aerospace, and FinTech.
- Affected industries: Aviation, Aerospace, Financial technology (FinTech), Software development / Technology specialists.
- Attack channels: linkedin, website.
- Impersonated: Recruiter for a major technology company (unnamed), Recruiter running a ‘purported hiring process’, Recruiter providing a time-limited access code.
Red flags to watch for
- Unsolicited recruiter contact pushing you to run code quickly
- Assessment delivered as a downloadable archive/project rather than a vetted testing platform
- Pressure to execute the project immediately
- Unusual instruction banning AI/security tools or review steps
- High-pressure deadline designed to reduce careful inspection
- Coding ‘test’ requires running an unfamiliar project on your workstation
- Time-limited ‘single-use’ access code intended to rush the target
- Recruiter insists on opening/running files quickly
- Nonstandard hiring workflow for code execution on your machine
Frequently asked questions
How did attackers get developers to run malware?
Fake recruiters contacted developers on job platforms with tech job offers and directed them to download a coding challenge hosted on cloud storage, encouraging them to run the project immediately, which secretly executed hidden malicious code alongside it.
What pressure tactics were used in this campaign?
Attackers used short deadlines of one to three hours and, in one case, a single-use six-digit access code valid only for a short time, pushing candidates to open the project quickly instead of reviewing it carefully.
Why did the ban on AI assistants matter?
One coding test explicitly banned the use of AI assistants, which researchers said may have been intended to prevent such tools from detecting the malicious code hidden in the project.
How did the attackers avoid detection?
The group used legitimate Microsoft Azure and Cloudflare infrastructure, and in some cases included the targeted organization's name in an Azure subdomain, making malicious traffic look like normal corporate network activity.
Read the video transcript
You get a LinkedIn message: a great dev role, and they want you to run a quick coding test. Looks legit, right? In a recent campaign, fake recruiters sent ‘coding challenges’ that secretly installed NodeRabbit or PollCat malware when devs ran the project from Amazon cloud storage or Azure links. The hook is pressure: 'Fix this app in three hours.' 'Single-use six-digit code.' 'Do not use AI assistants.' All designed so you run unknown code on your own machine without really checking it. If a recruiter you don’t know wants you to download and run a coding test, stop and send it to security before you ever execute the project.