logo

North Korea's Lazarus Group Deploys New Kaolin RAT via Fake Job Lures

ID: d64caddd-cfaa-56e3-af4d-6d82c7d75ec5

STIX ID: report--d64caddd-cfaa-56e3-af4d-6d82c7d75ec5

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-25

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The report documents Lazarus Group’s Operation Dream Job (summer 2023), where fabricated job-offer lures delivered a multi-stage infection chain that loads Kaolin RAT and then deploys the FudModule rootkit; the chain uses side‑loading, in-memory loaders (RollFling/RollSling/RollMid), steganographic C2 retrieval, and exploited a patched kernel driver vulnerability (CVE-2024-21338) to gain kernel read/write and disable security, enabling file enumeration/manipulation, process control, DLL loading, and C2 data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.