logo

Lazarus Group Targets Bitdefender Researcher with LinkedIn Recruiting Scam

ID: d37874b5-38b9-5646-a49a-40c97151e461

STIX ID: report--d37874b5-38b9-5646-a49a-40c97151e461

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2025-02-06

Date Updated: 2026-04-22

...
...

Bitdefender researchers observed a sophisticated Lazarus campaign that lured developers via fake LinkedIn job offers to download a cross-platform infostealer. The initial payload harvested browser logins and cryptocurrency wallet data, then executed a Python staging script that loaded modules (mlip.py, pay.py, bow.py) for clipboard monitoring, system/file exfiltration and browser data theft; a .NET component disabled Defender, configured a Tor proxy, fingerprinted the host, and fetched additional modules including a backdoor, keylogger and cryptominer. The report highlights multi-language, multi-stage tactics consistent with nation-state operations and urges developers to avoid running unverified code or suspicious repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.