Lazarus Hackers Utilize Fake LinkedIn Interview to Target AllSecure CEO
Sophisticated Phishing Campaign by Lazarus Group Uncovered
A sophisticated phishing campaign attributed to the notorious Lazarus Group, a North Korean hacking collective, has been uncovered. The attackers used a convincing fake job interview to target the CEO of a security firm, leveraging deepfake technology to build trust with the victim.
The Scam
The scam began with a seemingly legitimate job offer from a recruiter, who reached out to the CEO, Chris Papathanasiou, about a role at a company called 0G Labs. The message included a professional job description and a link to schedule a call with a hiring manager named Pedro Perez de Ayala. However, Papathanasiou became suspicious during the video call, noticing that the voice of the person on the screen did not match public videos of the real Pedro Ayala.
Malware and Fingerprinting
Further investigation revealed that the attackers may have used real-time deepfake technology or stolen identities to impersonate the hiring manager. The scam took a more sinister turn when the attackers sent Papathanasiou a folder containing a malicious payload, which executed when opened. The malware, dubbed BeaverTail, fingerprinted the victim’s machine, recording details such as the computer’s name, and pinging a secret server every five seconds.
Stealing Sensitive Information
The attackers’ ultimate goal was to steal sensitive information, including cryptocurrency wallets, browser passwords, SSH keys, and environment secrets. They also targeted MetaMask accounts and saved login data from browsers like Chrome and Brave.
Attribution and Recommendations
The attack was attributed to the Lazarus Group due to the distinctive methods used, including the specific coding style, malware employed, and servers previously linked to North Korean operations. To avoid falling victim to similar attacks, it is recommended to disable automatic tasks in coding software and exercise caution when recruiters push for the use of specific software.
“The use of deepfake technology and sophisticated social engineering tactics highlights the evolving nature of cyber threats. As attackers continue to refine their methods, it is essential for individuals and organizations to remain vigilant and take proactive measures to protect themselves against these types of attacks.”
