logo

Inside a North Korean Phishing Operation Targeting DevOps Employees

ID: 43a66e1d-ed71-5e01-b3cd-696be86ea89c

STIX ID: report--43a66e1d-ed71-5e01-b3cd-696be86ea89c

Feed Name: SecurityScorecard Blog

Threat Score
85/100

Date Published: 2025-03-07

Date Updated: 2026-04-29

...
...

SecurityScorecard's STRIKE Team detected and blocked a Lazarus-attributed campaign that used fake job offers on LinkedIn and malicious Bitbucket repositories to trick developers into running a NodeJS/JavaScript backdoor which fetched a base64/XOR-encoded second-stage credential-stealer; investigators identified C2 infrastructure (notably 147.124.214.129), a MongoDB storing victim interaction data, and victims in Pakistan, Brazil, and the United States.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.