Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Bitcoin price enters ‘fire sale’ zone – Is the BTC bottom near?

August 16, 2026

The stablecoin yield clash that won’t go away has banks, crypto battling over tradition

August 16, 2026

Ireland’s New AML Strategy Brings ‘Enhanced Checks’ on Private Crypto Wallets

August 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Lazarus Group Targets Developers in New Data Theft Campaign
Lazarus Group Targets Developers in New Data Theft Campaign
Security and Privacy

Lazarus Group Targets Developers in New Data Theft Campaign

January 17, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Notorious North Korea state-sponsored Lazarus group is targeting software developers in an ongoing campaign, researchers from SecurityScorecard have revealed.

The campaign, dubbed ‘Operation 99’, was identified on January 9. It is designed to steal sensitive data from developer environments, including source code, secrets and configuration files and cryptocurrency wallet keys.

The researchers said the campaign marks an evolution in the Lazarus group’s tactics, including shifting from broad phishing attempts to targeted attacks on developers in the tech supply chain.

The analysis also highlighted upgrades to the malware used by the group, such as enhanced obfuscation and adaptability capabilities.

The researchers were able to identify impacted victims across the globe, highlighting the extensive reach of the campaign.

The campaign is part of broader efforts by the group to generate revenue for the Democratic People’s Republic of Korea (DPRK) regime.

“The campaign’s focus on developers reflects a strategic evolution. By compromising the creators of technology, the attackers indirectly jeopardize the projects and enterprises these developers support. It’s a devastatingly efficient method of supply chain attack,” SecurityScorecard wrote.

Read now: Lazarus Group Targets Developers in Fresh VMConnect Campaign

Freelance Developers in the Crosshairs

The campaign has a specialized focus on developers seeking freelance work in the cryptocurrency sectors.

It begins with the attackers posing as recruiters contacting targets on platforms like LinkedIn about coding projects tied to fake recruitment schemes. These include project tests and code reviews.

This is in contrast to an observed campaign by Lazarus that targeted developers in October 2024, which targeted job seekers with fake job descriptions, the researchers noted.

See also  Lost keys have already cost billions of dollars, many more at risk — Polygon exec

In the new attack, the victim is directed to clone a malicious GitHub repository named “coin promoting Webapp.”

When the code from the repository is executed by the victim, it connects to command-and-control (C2) servers, hosted by the provider Stark Industries Solutions Ltd.

The provider’s IP address hosts and Apache server is configured to deliver various payloads, designed for second-stage execution on the victim’s machine.

The C2 servers use heavily obfuscated Python scripts, often compressed with ZLIB, to evade detection.

The infrastructure also dynamically tailors malware for specific targets, ensuring compatibility with the victim’s operating system and environment. The modular framework enables the malware to function across multiple platforms, including Windows, macOS and Linux.

The campaign deploys multi-stage malware system with modular components to steal a range of sensitive data from the developer’s device. These malware include:

  • Main99: A downloader that connects to C2 servers, retrieving additional payloads
  • Payload99/73: Implants capable of keylogging, clipboard monitoring and file exfiltration
  • Brow99/73: An implant designed for browser credential theft, such as passwords using the keychain
  • MCLIP: A dedicated implant for keyboard and clipboard monitoring

The researchers noted that by embedding the malware into developer workflows, the attackers can not only compromise individual victims but also the projects and systems they contribute to.

Developers Urged to Adopt Proactive Security Measures

SecurityScorecard said the campaign highlights the security vulnerabilities in developer ecosystem, which contain valuable intellectual property and digital assets.

The firm urged organizations to adopt proactive security measures to tackle threats. They should:

  • Deploy enhanced code repository verification, such as scrutinizing Git repositories before cloning
  • Use advanced endpoint security solutions to detect unusual activity
  • Verify recruiters and job offers on platforms like LinkedIn
  • Equip developers with the knowledge to identify red flags in emails, repositories and LinkedIn profiles
See also  US, UK intel agencies warn against new crypto malware: Report

Source link

campaign Data Developers Group Lazarus Targets Theft
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Solana Research Institute’s $18B Crash Claim Faces a Data Gap

August 16, 2026

BUILDon targets its 20-day EMA as short liquidations outpace longs

August 15, 2026

Trump Targets Cybercrime as Crypto Theft Drives 30% of Losses

August 15, 2026

French Tax Agency Admits Data Breach as Hacker Steals 678k Records

August 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bitcoin miner Bitfarms completes Stronghold acquisition, increases capacity to 623 MW

March 17, 2025

SOL Price Prediction – Why Solana Could See Sharp Downside Thrust

January 8, 2024

Australia’s proposed misinformation bill criticized for vague language

September 13, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin price enters ‘fire sale’ zone – Is the BTC bottom near?

August 16, 2026

The stablecoin yield clash that won’t go away has banks, crypto battling over tradition

August 16, 2026

Ireland’s New AML Strategy Brings ‘Enhanced Checks’ on Private Crypto Wallets

August 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,006.000.10%
  • ethereumEthereum(ETH)$1,880.640.00%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$607.10-0.50%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.00-0.20%
  • solanaSolana(SOL)$75.21-0.10%
  • tronTRON(TRX)$0.3315110.20%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.50%
  • HyperliquidHyperliquid(HYPE)$57.131.70%