logo

Lazarus Group’s IT Workers Scheme Hacker Group Caught Live On Camera

ID: 1730b3ab-c2e3-59dc-a971-e73263a5cd86

STIX ID: report--1730b3ab-c2e3-59dc-a971-e73263a5cd86

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Guru Baran

...
...

An investigation recorded Lazarus Group’s Chollima unit operating a remote‑IT‑worker scheme: researchers funneled DPRK operatives into long-running sandbox virtual machines that mimicked US developer laptops, exposing recruitment via GitHub/Telegram, identity theft and rented identities, use of consumer VPNs (Astrill), remote‑access tools (AnyDesk, Google Remote Desktop), and browser extensions/OTP tools to capture credentials. The honeypot revealed a human-driven intrusion campaign targeting finance, crypto, healthcare, and engineering firms, enabling theft of crypto assets, source code, and export‑controlled data and demonstrating the need for stronger identity verification and device controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.