logo

Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam

ID: fb77264e-16f4-590f-8713-af7b6807c598

STIX ID: report--fb77264e-16f4-590f-8713-af7b6807c598

Feed Name: Bitdefender Labs

Threat Score
85/100

Date Published: 2025-02-05

Date Updated: 2026-04-27

Author: Ionut Alexandru BALTARIU

...
...

Bitdefender Labs describes an active recruitment-style campaign attributed to North Korea-linked Lazarus actors that lures targets via fake LinkedIn job offers. The attackers deliver heavily obfuscated JavaScript that harvests browser credentials and crypto-extension data, then stages multi-layered Python scripts and a .NET binary which disable defenses, establish Tor-based C2, exfiltrate sensitive data (including wallets, credentials, and system fingerprints), run keyloggers and crypto-miners, and pursue persistence across Windows, macOS, and Linux; the report includes indicators, technical analysis, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.