North Korea's Lazarus APT Evolves Developer-Recruitment Attacks
ID: 7a27ba23-0c92-5893-bdf1-5489e310d1b9
STIX ID: report--7a27ba23-0c92-5893-bdf1-5489e310d1b9
Feed Name: Dark Reading
Date Published: 2025-01-15
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
SecurityScorecard's STRIKE team discovered Operation 99, a Lazarus APT campaign that uses fake recruiter profiles on LinkedIn and malicious Git repositories to trick freelance developers into cloning repositories that deploy cross-platform modular malware (Main99, Payload 99/73, brow99/73, MCLIP). The implants connect to command-and-control servers and perform keylogging, clipboard monitoring, browser credential theft, source-code and configuration exfiltration, and cryptocurrency wallet theft; attackers use AI-generated profiles, compromised LinkedIn accounts, and advanced obfuscation to increase credibility and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
