Iranian Hackers Use Fake Recruiter Coding Test

Hackaday · High sophistication
Last updated September 11, 2026

A suspected Iranian government-backed hacking group approached people while pretending to be recruiters, then used a “coding challenge” as the hook to get targets to run malicious code. Victims were sent a ZIP file containing a trojanized Node.js project that infects the machine when it’s built/compiled, giving the attackers remote access across Windows, macOS, and Linux.

Key findings

  • Attackers posed as recruiters and sent targets a ZIP file with a “coding challenge.”
  • The ZIP contained a trojaned Node.js project that infected systems when compiled/built.
  • The campaign targeted specific individuals via spear-phishing and deployed cross-platform remote access tooling.
  • The malware attempted to identify/collect data related to major security products and Google/Microsoft-related directories.

Who’s being targeted

  • Commonly targeted roles: Engineering, IT, Security, Recruiting/HR (to recognize impersonation patterns), Executives and high-profile staff (often targeted individuals).
  • Affected industries: Software development, Professional services, Government and public sector (targeted individuals).
  • Attack channels: email.
  • Impersonated: Recruiter / hiring team.

Awareness takeaways

  • Treat unexpected “recruiter” files (especially ZIPs) as high-risk; don’t open or run them on work devices.
  • Assume building/compiling third-party code can execute commands; only run coding tests in a safe, isolated environment approved by IT/security.
  • Be cautious of “skills tests” that require enabling scripts/plugins or running build steps; verify the recruiter and company independently before proceeding.

Red flags to watch for

  • Unsolicited recruiter message pushing an attached ZIP/code project
  • Instructions require building/running a project from an unknown source
  • Pressure to execute build scripts as part of the screening step
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email from a ‘recruiter’: they love your background and want you to do a quick coding challenge in the attached ZIP. But this isn’t just a test. Iranian government-backed groups are sending trojaned Node.js projects, when you build the project, it silently installs remote access tools on Windows, macOS, or Linux. Here’s the nasty part: the moment you hit build, that ‘challenge’ can run any command it wants, scanning for security tools, digging through Google and Microsoft folders, and phoning home for remote control. If a recruiter sends you a ZIP coding test, stop. Before you build or run anything, forward it to Security and ask, “Is it safe to run this on my work machine?”

Similar attacks

Fake Recruiters Push “Coding Tests” as RAT Traps

Fake Recruiters Push “Coding Tests” as RAT Traps

Researchers say the Iran-linked group Nimbus Manticore posed as recruiters on LinkedIn and job platforms to send developers “technical challenge” ZIP files that secretly installed cross-platform remote access trojans. The lures used urgency (short test windows) and realistic developer workflows…

September 1, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
SilkParasite Hits Central Asia via Phish Docs

SilkParasite Hits Central Asia via Phish Docs

Bitdefender reports a China-linked espionage campaign (“SilkParasite”) targeting government bodies in Central Asia using spearphishing emails carrying malicious Microsoft Office documents. The malware is designed to stay quiet and blend in, including using Google Drive as a communications channel…

August 20, 2026
APT42 Lures Targets With Podcast Invites

APT42 Lures Targets With Podcast Invites

Researchers report Iranian-linked APT groups using legitimate cloud services to hide command-and-control traffic, and separately running spear-phishing campaigns. In the phishing cases, attackers used credible “podcast” or “interview invitation” themes to persuade targets to open a Windows shortcut…

August 17, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Recruiters Target Job Seekers With Malicious PDFs

Fake Recruiters Target Job Seekers With Malicious PDFs

North Korea-linked Lazarus Group ran a “Dream Job” campaign targeting people applying for defense and aerospace jobs by posing as recruiters on LinkedIn and other platforms. Victims were sent malicious PDF files; opening them enabled a backdoor and then an exploit for a Windows zero-day…

August 12, 2026