0x Zero X.txt
Intelligence Archive

Public Reports

Operational write-ups from authorized adversary simulation campaigns, including TTP emulation, evasion engineering, and full attack-lifecycle replication in isolated environments.

Unmasking NodeRabbit: A Full Adversary Simulation of an Iranian Fake Recruiter RAT
Featured Report ID: 10
Sep 08, 2026 17 MIN READ

Unmasking NodeRabbit: A Full Adversary Simulation of an Iranian Fake Recruiter RAT

An Iranian government espionage group poses as recruiters on LinkedIn, using trojanized "technical assessment" coding challenges to deliver a custom Node.js backdoor.

#NodeRabbit #Iranian APT #Adversary Simulation
Access Full Intel arrow_forward