logo

Lazarus Group Unleashes New Malware Tactic Against Global Developers

ID: b9fc6866-5d5e-56f0-8966-799e3f193e3e

STIX ID: report--b9fc6866-5d5e-56f0-8966-799e3f193e3e

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-02-14

Date Updated: 2026-04-13

Author: Mandvi

...
...

**Executive Summary:** Operation Marstech Mayhem is a Lazarus Group supply-chain campaign that embeds a new implant, "Marstech1", in malicious GitHub repositories and NPM packages to infect developer systems, persist via a JavaScript loader connected to C2 infrastructure, and exfiltrate cryptocurrency wallet credentials and authentication tokens; the campaign uses sophisticated social engineering (LinkedIn/Discord), VPNs/proxies for evasion, and was linked to 233 victims across multiple countries in January 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.