Trojanized VNC apps leveraged in defense-targeted Lazarus Group attacks

North Korea’s Lazarus Group, also known as TEMP.Hermit or Hidden Cobra, has been continuing its Operation Dream Job campaign with new intrusions leveraging trojanized Virtual Network Computing apps targeted at defense industry and nuclear engineers, according to The Hacker News. Kaspersky researchers revealed that malicious job interview apps have been leveraged by Lazarus facilitate the distribution of the LPEClient backdoor with compromised host profiling capabilities, an updated COPPERHEDGE malware version with arbitrary command execution and data exfiltration functionality, and a custom malware for file transmission.

Source: SC Magazine

 


Date:

Categorie(s):

Tag(s):