Lazarus Group’s IT Workers Scheme Hacker Group Caught Live On Camera
ID: 1730b3ab-c2e3-59dc-a971-e73263a5cd86
STIX ID: report--1730b3ab-c2e3-59dc-a971-e73263a5cd86
Feed Name: cybersecurityNews.com
An investigation recorded Lazarus Group’s Chollima unit operating a remote‑IT‑worker scheme: researchers funneled DPRK operatives into long-running sandbox virtual machines that mimicked US developer laptops, exposing recruitment via GitHub/Telegram, identity theft and rented identities, use of consumer VPNs (Astrill), remote‑access tools (AnyDesk, Google Remote Desktop), and browser extensions/OTP tools to capture credentials. The honeypot revealed a human-driven intrusion campaign targeting finance, crypto, healthcare, and engineering firms, enabling theft of crypto assets, source code, and export‑controlled data and demonstrating the need for stronger identity verification and device controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
