logo

Researchers spotted Lazarus’s remote IT workers in action

ID: 7b46a5f5-5aad-539e-ae7e-b3a03a752b8d

STIX ID: report--7b46a5f5-5aad-539e-ae7e-b3a03a752b8d

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-12-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers captured Lazarus (Famous Chollima) operators running a remote-worker infiltration scheme: attackers posed as recruiters to obtain victims' identities and remote access, used AI tools to pass interviews, browser OTP generators to bypass 2FA, Astrill VPN for routing, and Google Remote Desktop configured via PowerShell to maintain persistent control — all observed in sandboxed virtual machines without deployment of malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.