logo

North Korea's Lazarus APT Evolves Developer-Recruitment Attacks

ID: 7a27ba23-0c92-5893-bdf1-5489e310d1b9

STIX ID: report--7a27ba23-0c92-5893-bdf1-5489e310d1b9

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-01-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

SecurityScorecard's STRIKE team discovered Operation 99, a Lazarus APT campaign that uses fake recruiter profiles on LinkedIn and malicious Git repositories to trick freelance developers into cloning repositories that deploy cross-platform modular malware (Main99, Payload 99/73, brow99/73, MCLIP). The implants connect to command-and-control servers and perform keylogging, clipboard monitoring, browser credential theft, source-code and configuration exfiltration, and cryptocurrency wallet theft; attackers use AI-generated profiles, compromised LinkedIn accounts, and advanced obfuscation to increase credibility and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.