North Korea's Lazarus Group Deploys New Kaolin RAT via Fake Job Lures
ID: d64caddd-cfaa-56e3-af4d-6d82c7d75ec5
STIX ID: report--d64caddd-cfaa-56e3-af4d-6d82c7d75ec5
Feed Name: The Hacker News
The report documents Lazarus Group’s Operation Dream Job (summer 2023), where fabricated job-offer lures delivered a multi-stage infection chain that loads Kaolin RAT and then deploys the FudModule rootkit; the chain uses side‑loading, in-memory loaders (RollFling/RollSling/RollMid), steganographic C2 retrieval, and exploited a patched kernel driver vulnerability (CVE-2024-21338) to gain kernel read/write and disable security, enabling file enumeration/manipulation, process control, DLL loading, and C2 data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
