logo

Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam

ID: 69a4e7e8-b155-59f3-9f24-2214c053c9c5

STIX ID: report--69a4e7e8-b155-59f3-9f24-2214c053c9c5

Feed Name: Bitdefender Labs

Threat Score
88/100

Date Published: 2025-02-05

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

Bitdefender Labs reports an active Lazarus Group campaign that leverages fake LinkedIn job offers to trick targets into running a multi-stage, cross-platform malware chain: an obfuscated JavaScript stealer collects browser and crypto-extension data, then downloads recursive Python modules (mlip/pay/bow) and a .NET stager that disables defenses, configures Tor C2, exfiltrates credentials and sensitive files, logs keystrokes, and can deploy crypto-mining and backdoor modules; the campaign targets professionals across industries and IOCs are provided to Bitdefender Advanced Threat Intelligence users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.