logo

Beware of Contacts through LinkedIn: They Target Your Organization’s Property, Not Yours

ID: 0c4fa2a2-6616-5c8f-acbb-c98ba9ac78bf

STIX ID: report--0c4fa2a2-6616-5c8f-acbb-c98ba9ac78bf

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2025-01-20

Date Updated: 2026-04-19

Author: 朝長 秀誠 (Shusei Tomonaga)

...
...

JPCERT/CC warns that Lazarus-linked campaigns are actively exploiting LinkedIn as an initial access vector—often via hijacked legitimate accounts—to contact targets (notably defense and cryptocurrency organizations), switch communications to Skype/WhatsApp/Telegram, and deliver malicious files (Word, ZIP/LNK, MSI) that install cross-platform malware. The report details three operations (Dream Job, DangerousPassword, AppleJeus), notes persistent activity since 2019, and recommends restricting SNS use on work devices and implementing protective measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.