logo

Lazarus Group Targets Nuclear Industry with CookiePlus Malware

ID: d55e0d67-699d-54b8-a369-d012fa631f73

STIX ID: report--d55e0d67-699d-54b8-a369-d012fa631f73

Feed Name: HackRead

Threat Score
90/100

Date Published: 2024-12-23

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Securelist/Kaspersky reports that the Lazarus Group has shifted focus to targeting personnel in the nuclear industry using fake job postings (Operation DreamJob) to deliver modular, in-memory malware (notably a plugin called CookiePlus) via Ranid Downloader and related payloads; the group also leveraged a Chrome zero-day and macOS-focused techniques (RustyAttr), demonstrating high sophistication and active operations in January 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.