Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Lazarus Group targets Web3 developers with fake LinkedIn profiles in Operation 99
Global Security

Lazarus Group targets Web3 developers with fake LinkedIn profiles in Operation 99

AdminBy AdminJanuary 15, 2025No Comments3 Mins Read
Fake LinkedIn Profiles
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 15, 2025Ravi LakshmananCryptocurrency / Malware

Fake LinkedIn profiles

The Lazarus Group, linked to North Korea, has been attributed to a new cyber attack campaign called Operation 99 targeting software developers looking for freelance Web3 and cryptocurrency experts to deliver malware.

“The campaign starts with fake recruiters posing on platforms like LinkedIn, luring developers with project tests and code reviews,” said Ryan Sherstabitov, SVP of Threat Research and Intelligence at SecurityScorecard. said in a new report released today.

“Once the victim takes the bait, they are told to clone a malicious GitLab repository that appears harmless but is filled with disaster. The cloned code connects to command and control (C2) servers, embedding malware in the victim’s environment.”

Victims of the campaign were found all over the world, with a significant concentration recorded in Italy. Fewer victims are in Argentina, Brazil, Egypt, France, Germany, India, Indonesia, Mexico, Pakistan, Philippines, UK and USA

Cyber ​​security

The cybersecurity company said the campaign it discovered on January 9, 2025, is based on tactics of work topics previously seen in Lazarus attacks such as Operation Dream Job. (aka NukeSped) to specifically focus on Web3 and cryptocurrency developers.

What makes Operation 99 unique is that it lures developers with coding projects in a sophisticated recruitment scheme that involves creating fake LinkedIn profiles, which are then used to direct them to fake GitLab repositories.

Fake LinkedIn profiles

The ultimate goal of the attacks is to deploy data-stealing implants capable of extracting source code, secrets, cryptocurrency wallet keys, and other sensitive data from the development environment.

This includes Main5346 and its variant Main99, which serves as a bootloader for three additional payloads –

  • Payload99/73 (and its functionally similar Payload5346), which collects system data (such as files and clipboard contents), terminates web browser processes, performs arbitrary actions, and establishes a persistent connection to the C2 server
  • Brow99/73, which steals data from web browsers to facilitate credential theft
  • MCLIP, which monitors and exfiltrates keyboard and clipboard activity in real time
Cyber ​​security

“By compromising developer accounts, attackers not only steal intellectual property, but also gain access to cryptocurrency wallets, enabling direct financial theft,” the company said. “Targeted theft of private and secret keys could lead to millions in stolen digital assets, furthering Lazarus Group’s financial goals.”

The architecture of the malware is modular, flexible and capable of running on Windows, macOS and Linux operating systems. It also serves to highlight the ever-evolving and adaptive nature of nation-state cyber threats.

“For North Korea, hacking is a lifeline that brings in profits,” Sherstabitov said. “The Lazarus Group has consistently funneled stolen cryptocurrency to fuel the regime’s ambitions, amassing staggering sums. With the growth of the Web3 and cryptocurrency industries, Operation 99 is targeting these fast-growing sectors.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025

1500+ Minecraft players infected with malicious Java software

June 18, 2025

Water Prought works 76 GitHub accounts for a multi -stage malicious company

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.