North Koreans clone open source projects to plant backdoors, steal credentials
ID: 28c7bdac-15ee-529d-8e5c-5cd39c62247e
STIX ID: report--28c7bdac-15ee-529d-8e5c-5cd39c62247e
Feed Name: The Register (Security)
SecurityScorecard attributes a global supply-chain campaign called 'Phantom Circuit' to North Korea's Lazarus Group, in which attackers created malicious forks of legitimate open-source and cryptocurrency-related projects to deliver obfuscated backdoors that stole credentials, tokens, and system information; researchers observed multiple waves affecting hundreds–thousands of developers, identified C2 servers and an administrative platform, and documented layered obfuscation and data exfiltration to cloud storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
