DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies
ID: 17faa98a-afca-58ac-b4cb-08aa649cd080
STIX ID: report--17faa98a-afca-58ac-b4cb-08aa649cd080
Feed Name: The Hacker News
**Executive summary:** The report describes a coordinated set of DPRK-linked operations where threat actors impersonate remote IT workers on platforms like LinkedIn to obtain employment and access, run recruiting-based social engineering ('Contagious Interview') to trick candidates into executing malware, deploy a modular JavaScript RAT (Koalemos) via malicious npm packages and VS Code task files, and use blockchain techniques for resilient C2 and crypto money-laundering; it also notes the Labyrinth Chollima group's segmentation into specialized clusters that share tools and infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
