Researchers Uncover Lazarus Group Admin Layer for C2 Servers
ID: 95f90422-efc7-511f-a417-5d86d48501c4
STIX ID: report--95f90422-efc7-511f-a417-5d86d48501c4
Feed Name: Dark Reading
Threat Score
SecurityScorecard uncovered a Lazarus Group operation (Operation 99 / Phantom Circuit) targeting cryptocurrency companies and developers worldwide by tricking developers into cloning malicious GitHub repositories, deploying obfuscated backdoors and data-stealing payloads; the adversary centrally manages C2 via a hidden web admin layer, uses Astrill VPNs and proxy chains to mask origins, and has been linked with high confidence to Pyongyang with over 230 victims identified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
