Cyber Hacking News

North Korean hackers lure crypto experts with fake job offers

0

North Korean Lazarus hacking group were found impersonating Coinbase to target employees in the fintech industry.

The notorious hacking group were involved in the new social engineering campaign by approaching the targets over LinkedIn to present a job offer and hold a preliminary discussion.

A security researcher at Malwarebytes, Hossein Jazi who has been following Lazarus activity closely since February 2022 had discovered this attack and stated that they are targeting candidates suitable for the role of “Engineering Manager, Product Security.”

Coinbase is one of the world’s largest cryptocurrency exchange platforms, that allows Lazarus to lay the ground for a profitable and attractive job offer at a prestigious organization.

When victims download a PDF about the job position, they are actually getting a malicious executable using a PDF icon. In this case, the file is named “Coinbase_online_careers_2022_07.exe,” which will display the decoy PDF document that gets executed while also loading a malicious DLL.

Once executed, the malware will use GitHub as a command and control server to receive commands to perform on the infected device.

State-sponsored North Korean hacking groups are known for launching financially motivated attacks against banks, cryptocurrency exchanges, NFT marketplaces, and individual investors with significant holdings.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

GwisinLocker ransomware targets firms in South Korea

Previous article

Twilio discloses data breach after SMS phishing attack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *