{"id":2022,"date":"2025-02-16T10:04:23","date_gmt":"2025-02-16T10:04:23","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/02\/16\/lazarus-group-infostealer-malwares-attacking-developers-in-new-campaign\/"},"modified":"2025-02-16T10:04:23","modified_gmt":"2025-02-16T10:04:23","slug":"lazarus-group-infostealer-malwares-attacking-developers-in-new-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/02\/16\/lazarus-group-infostealer-malwares-attacking-developers-in-new-campaign\/","title":{"rendered":"Lazarus Group Infostealer Malwares Attacking Developers In New Campaign"},"content":{"rendered":"<p>    Lazarus Group Infostealer Malwares Attacking Developers In New Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The notorious Lazarus Group, a North Korean Advanced Persistent Threat (APT) group, has been linked to a sophisticated campaign targeting software developers.<\/p>\n<p>This campaign involves the use of infostealer malware, designed to steal sensitive information from developers\u2019 systems.<\/p>\n<p>The attack leverages social engineering tactics, including fake job interviews and compromised <a href=\"https:\/\/cybersecuritynews.com\/new-malicious-npm-packages-attack-amazon-slack\/\" target=\"_blank\" rel=\"noreferrer noopener\">NPM packages<\/a>, to deceive developers into executing malicious scripts.<\/p>\n<p>The malware campaign involves a multi-stage modular approach, using techniques such as Base64 encoding and zlib compression to obfuscate the malicious code.<\/p>\n<p>Threat Intelligence Researcher, Rayssa Cardoso <a href=\"https:\/\/medium.com\/@rayssac\/infostealer-malware-linked-to-lazarus-group-campaigns-a510ad5f3e4f\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">detected<\/a> a key component of the attack is a Python script that uses a lambda function to decode and execute the malware:-<\/p>\n<pre class=\"wp-block-code\"><code>_ = lambda __ : __import__('zlib').decompress(__import__('base64').b64decode(__[::-1]));exec((_)<\/code><\/pre>\n<p>This script reverses the input string, decodes it using Base64, decompresses the result with zlib, and then executes the reconstructed Python code using the <code>exec()<\/code> function.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Campaign Structure<\/strong><\/h2>\n<p>The malware structure includes several files and folders:-<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>script.py<\/strong>: The main file containing instructions to call other script functions.<\/li>\n<li>\n<strong>sysinfo folder<\/strong>: Contains files for detecting the victim\u2019s operating system and communicating with the Command and Control (C2) server on port 1224.<\/li>\n<li>\n<strong>n2 folder<\/strong>: Includes files for reading registry keys, storing collected information, installing required libraries, and collecting system and geolocation data.<\/li>\n<\/ul>\n<p>Lazarus Group uses social engineering tactics like the \u201cClickFix\u201d method, where users are tricked into executing malicious scripts by clicking on seemingly legitimate buttons.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgxx9Bh31MHRBdGLF0_5YJdIUnZUH0NpQJDm9TWE1GH9fTUaALlE2VV8AuzPFSbkc6iusd29qCaUf2Ek0lFueoGBlredrCi8kG8mWWLJ1o5WKDfiIvBSlhNeTwyXiwEyBEmIMxji5kDXEb0plJcSuCo0vn0fHRF76Qkwp0BdkNq8JWYUeoR8hcIzNRNqzg\/s16000\/ClickFix%2520Campaign%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">ClickFix Campaign (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>Another tactic involves fake recruiter profiles on platforms like LinkedIn and GitHub, inviting developers to participate in <a href=\"https:\/\/cybersecuritynews.com\/north-korean-posing-recruiters\/\" target=\"_blank\" rel=\"noreferrer noopener\">online interviews<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiFGnxLL742dYfXPe6EjjnJhachbbH8FcZ52rJETft8L5XlOYwvKhC3r6bDUDZcfbvrz9R102759vUS7WU54p_U0Kf5A8QHj6mS9mvooMh7mOckzfTiNhj5i7sD30_KHpad6A2Yx1c_BRQoV5VL9_1-qb3JsEDCAMCPc5lKrcBepgc5-vDWxm2SMdnGDvg\/s16000\/Obfuscated%2520Code%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Obfuscated Code (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>During these interviews, candidates are asked to execute <a href=\"https:\/\/cybersecuritynews.com\/chrome-vulnerability-malicious-code\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious code<\/a>, leading to the installation of malware.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi2gNkM4-9kYaHEAmXiR04nPok84yZHYquz-qInPQsG0PXmDDduj9aMj-SchL2xEy-3aYIf0VOYUlSyLWwOaclXF0AigBwn-27AhXhW1aqLnbjesDJ1Bef_jGAMP28NMJbxVn40l8bprIrytJ39bww30-TclV_r9qIezRd5OnP_JHz9lHReApyx-OxpDQs\/s16000\/Contagious%2520Interview%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Contagious Interview (Source \u2013 Medium)<\/figcaption><\/figure>\n<p>The campaign involves several types of malware, including:-<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>BeaverTail (JavaScript)<\/strong>: Acts as a loader.<\/li>\n<li>\n<strong>InvisibleFerret (Python)<\/strong>: Functions as a backdoor and infostealer.<\/li>\n<li>\n<strong>Tsunami<\/strong>: A backdoor, RAT, and infostealer used in the Operation99 campaign.<\/li>\n<\/ul>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhaClK7o-fNB6zQImB73l3HGx3BY88WrAWZWBImTVgzsyWLOnGtCaiBv0GvNZsjmk8L5i8web0dRV7aJTYMQV5HiAUqV0SnpGWWO1N9FJ8Xp-xOhlNeLCySTCNwizuNUKKMeRydUHMqd7OUPj8DlzswAEUJ15pWS2ZXOuBC4iDGQAGZ6Ji3D_ZVcA7QN_g\/s16000\/Contagious%2520Interview%2520Cmpaign%2520Chain%2520%28Source%2520-%2520Medium%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Contagious Interview Cmpaign Chain (Source \u2013 Medium)<\/figcaption><\/figure>\n<\/div>\n<p>The use of sophisticated social engineering tactics and obfuscated malware shows the need for strict vigilance and robust <a href=\"https:\/\/cybersecuritynews.com\/how-can-businesses-ensure-their-cybersecurity-measures-are-adequate\/\" target=\"_blank\" rel=\"noreferrer noopener\">cybersecurity measures<\/a>.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Indicators of Compromise (IoC)<\/strong><\/h2>\n<ul class=\"wp-block-list\">\n<li>5.253.43[.]122:1224<\/li>\n<li>41.208.185[.]235<\/li>\n<li>95.164.7[.]171:8637<\/li>\n<li>http[:]\/\/ip-api[.]com\/json<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>MITRE ATT&amp;CK TTPs<\/strong><\/h2>\n<ul class=\"wp-block-list\">\n<li>T1027 \u2013 Obfuscated Files or Information<\/li>\n<li>T1027.002 \u2013 Obfuscated Files or Information: Software Packing<\/li>\n<li>T1204.002 \u2013 User Execution: Malicious File<\/li>\n<li>T1564.001 \u2013 Hide Artifacts: Hidden Files and Directories<\/li>\n<li>T1082 \u2013 System Information Discovery<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/analysis\/lookup?utm_source=csn_feb&amp;utm_medium=article&amp;utm_campaign=ti&amp;utm_content=lookup-tasks-1&amp;utm_term=120225\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/lazarus-group-infostealer-malwares-attacking-developers\/\">Lazarus Group Infostealer Malwares Attacking Developers In New Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/lazarus-group-infostealer-malwares-attacking-developers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lazarus Group Infostealer Malwares Attacking Developers In New Campaign The notorious Lazarus Group, a North Korean Advanced Persistent Threat (APT) group, has been linked to a sophisticated campaign targeting software developers. This campaign involves the use of infostealer malware, designed to steal sensitive information from developers\u2019 systems. The attack leverages social engineering tactics, including fake [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[701,63,700],"tags":[130],"class_list":["post-2022","post","type-post","status-publish","format-standard","hentry","category-cyber-attack","category-cyber-security-news","category-cyberattack-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2022"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2022"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2022\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}