Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Iranian hackers have been using a sophisticated tactic to deliver malicious software, exploiting vulnerabilities in coding test platforms to gain unauthorized access to target devices. The group’s modus operandi involves posing as recruiters or HR personnel, luring unsuspecting individuals into participating in online coding tests that promise lucrative job opportunities.

These seemingly legitimate coding tests are actually designed to deliver cross-platform Remote Access Trojans (RATs), allowing the attackers to take control of the compromised devices. The RATs can be used to steal sensitive information, disrupt operations, or even create backdoors for further malicious activity. The Iranian hackers’ campaign has affected individuals and organizations worldwide, with reports indicating that various sectors have been targeted, including tech, finance, and government.

To understand how this works, it’s essential to grasp the basics of coding tests. These platforms often provide users with sample code or challenges to complete within a specific timeframe. Unbeknownst to participants, some coding test platforms can be manipulated to inject malicious code into the user’s device. This is achieved by exploiting vulnerabilities in the platform’s architecture or through social engineering tactics.

The Iranian hackers’ use of coding tests as a vector for delivering RATs is particularly insidious because it plays on the trust and legitimacy that comes with participating in online assessments. This tactic also highlights the importance of verifying the authenticity of job offers, especially those that seem too good to be true. With the rise of remote work and digital collaboration tools, organizations must ensure their security protocols account for these evolving threats.

The Iranian hackers’ campaign has significant implications for cybersecurity professionals and individuals alike. It underscores the need for more robust security measures in coding test platforms and highlights the importance of educating users about online safety best practices. Furthermore, this incident serves as a reminder that even seemingly legitimate activities can be exploited by malicious actors, emphasizing the importance of vigilance and due diligence in all online interactions.

Ultimately, this incident should prompt individuals to exercise caution when engaging with online job opportunities or participating in coding tests from unfamiliar sources. By being aware of these tactics and taking steps to verify authenticity, we can better protect ourselves against sophisticated threats like those posed by Iranian hackers.


Source: The Hacker News — 2026-09-01