Lazarus Group’s Latest Cyber Espionage Tactics Involving LinkedIn
ID: fc2d7f57-29c4-503a-80b8-5b6fdc0b3773
STIX ID: report--fc2d7f57-29c4-503a-80b8-5b6fdc0b3773
Feed Name: SOCRadar Blog
Threat Score
The article details a Lazarus Group cyber-espionage campaign where attackers pose as recruiters on LinkedIn to trick finance and travel professionals into fetching a malicious GitHub/Bitbucket repository; the repository contains obfuscated scripts that install a cross-platform JavaScript info-stealer (targeting cryptocurrency wallet browser extensions) and a Python backdoor, and the report includes IoCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
