Lazarus Group’s Latest Cyber Espionage Tactics Involving LinkedIn

2025-02-12 SOCRadar

https://socradar.io/lazarus-groups-cyber-espionage-involving-linkedin/

Thumbnail for Lazarus Group’s Latest Cyber Espionage Tactics Involving LinkedIn

Lazarus operators used LinkedIn recruiter personas to approach finance and travel-sector targets with a supposed decentralized exchange project. After collecting a CV or GitHub link, the attackers shared a GitHub or Bitbucket repository containing obfuscated scripts that downloaded next-stage payloads from remote infrastructure. The campaign used a cross-platform JavaScript infostealer against browser cryptocurrency wallet extensions on Windows, macOS, and Linux, then installed a Python backdoor for persistence, clipboard monitoring, remote access, and additional malware delivery. Reported indicators included support.cloudstore[.]business, support.docsend[.]site, 104.168.165[.]203, and a filedn[.]com URL.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://filedn.com/lY24cv0Ifefb… 2024-11-13 2025-02-12
DOMAIN filedn.com 2024-11-13 2025-02-12
IPv4 104.168.165.203 2024-07-15 2025-02-12
IPv4 104.168.157.45 2024-07-15 2025-02-12

Related Actors

Related Reports

« Back