あなたではなく組織の財産を狙うLinkedIn経由のコンタクトにご用心

2025-01-10 JPCERT Beware of LinkedIn Contacts Targeting Your Organization's Assets, Not You

https://blogs.jpcert.or.jp/ja/2025/01/initial_attack_vector.html

Thumbnail for あなたではなく組織の財産を狙うLinkedIn経由のコンタクトにご用心

JPCERT/CC reviews Lazarus use of LinkedIn as an initial access vector against organizations, including cryptocurrency-related and defense-industry targets. The activity includes suspicious recruiter-style contact, pressure to move conversations from LinkedIn to Skype or WhatsApp, attempts to make victims download and execute files, and follow-up questions about execution status or the victim environment. The report connects these behaviors to Lazarus and TraderTraitor-style operations and recommends limiting SNS use on business hosts and hardening access controls.

Related Actors

Related Reports

« Back