Investigating the campaigns of Lazarus Group targeting developers and companies

2024-07-21 Coinmonks

https://medium.com/coinmonks/investigating-the-activity-of-lazarus-group-targeting-developers-and-companies-182611f89cf0

Thumbnail for Investigating the campaigns of Lazarus Group targeting developers and companies

The Coinmonks investigation attributes suspicious developer, recruiter, company, and GitHub activity to Lazarus Group with moderate confidence, linking it to Contagious Interview and Wagemole style campaigns. The source describes fake GitHub identities, high-follower node accounts, copied repositories, phishing domains that impersonate or redirect to GitHub, and fake developer websites used to make fraudulent personas look credible. It also cites GitHub's high-confidence attribution of related activity to a group supporting North Korean objectives, tracked under labels including Lazarus Group, APT38, Jade Sleet, BlueNoroff, TraderTraitor, and Stardust Chollima. For defenders, the report is useful for tracking DPRK social-engineering infrastructure aimed at developers, Web3 companies, and hiring workflows.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://developers.sh 2024-07-21 2024-07-21
URL https://ambitio.club/ 2024-07-21 2024-07-21
URL https://dev.ambitio.in/ 2024-07-21 2024-07-21
URL https://cipherstash.com/ 2024-07-21 2024-07-21
URL https://cipheristash.com/ 2024-07-21 2024-07-21
URL https://credentee.io/ 2024-07-21 2024-07-21
DOMAIN certifycchbc-stejdzing.credente… 2024-07-21 2024-07-21
DOMAIN credentee.io 2024-07-21 2024-07-21
DOMAIN developers.sh 2024-07-21 2024-07-21
DOMAIN dev.ambitio.in 2024-07-21 2024-07-21
DOMAIN ambitio.club 2024-07-21 2024-07-21
DOMAIN cipherstash.com 2024-07-21 2024-07-21
DOMAIN cipheristash.com 2024-07-21 2024-07-21

Related Actors

Related Reports

« Back