logo

Operation 99: North Korea’s Cyber Assault on Software Developers

ID: 38fac0a5-5f09-5ec3-884c-e3a1fb150c18

STIX ID: report--38fac0a5-5f09-5ec3-884c-e3a1fb150c18

Feed Name: SecurityScorecard Blog

Threat Score
90/100

Date Published: 2025-08-05

Date Updated: 2026-04-29

...
...

SecurityScorecard STRIKE uncovered 'Operation 99', a January 2025 Lazarus Group campaign that lures software developers with fake recruiter profiles and malicious GitLab repositories to deploy modular, cross-platform implants (Main99/Main5346, Payload99/73, Brow99/73, MCLIP). The implants enable browser credential theft, clipboard and keylogging exfiltration, file theft, and persistent C2 connectivity via heavily obfuscated Python servers hosted by a front company; the campaign targets source code, secrets, and cryptocurrency wallet keys, posing a high supply-chain and financial risk to developer ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.