Lazarus Group Targets Organizations with Sophisticated LinkedIn Recruiting Scam
ID: fb77264e-16f4-590f-8713-af7b6807c598
STIX ID: report--fb77264e-16f4-590f-8713-af7b6807c598
Feed Name: Bitdefender Labs
Bitdefender Labs describes an active recruitment-style campaign attributed to North Korea-linked Lazarus actors that lures targets via fake LinkedIn job offers. The attackers deliver heavily obfuscated JavaScript that harvests browser credentials and crypto-extension data, then stages multi-layered Python scripts and a .NET binary which disable defenses, establish Tor-based C2, exfiltrate sensitive data (including wallets, credentials, and system fingerprints), run keyloggers and crypto-miners, and pursue persistence across Windows, macOS, and Linux; the report includes indicators, technical analysis, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
