Lazarus Group Targets Nuclear Industry with CookiePlus Malware
ID: d55e0d67-699d-54b8-a369-d012fa631f73
STIX ID: report--d55e0d67-699d-54b8-a369-d012fa631f73
Feed Name: HackRead
Threat Score
Securelist/Kaspersky reports that the Lazarus Group has shifted focus to targeting personnel in the nuclear industry using fake job postings (Operation DreamJob) to deliver modular, in-memory malware (notably a plugin called CookiePlus) via Ranid Downloader and related payloads; the group also leveraged a Chrome zero-day and macOS-focused techniques (RustyAttr), demonstrating high sophistication and active operations in January 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
