InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Lazarus Group uses fake coding tests to spread malware
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Lazarus Group uses fake coding tests to spread malware
Technology

Lazarus Group uses fake coding tests to spread malware

September 16, 2024 4 Min Read
Share
Fake Coding Tests
SHARE

Cybersecurity researchers have discovered a new set of malicious Python packages targeting software developers under the guise of coding assessments.

“The new samples were traced to a GitHub project that has been linked to previous targeted attacks that lure developers using fake job interviews,” said Carlo Zanchi, a researcher at Reversing Lab.

The activity is assessed to be part of an ongoing campaign called VMConnect, which first came to light in August 2023. There are indications that it is the work of the North Korea-backed Lazarus Group.

North Korean threat actors have widely used job interviews as an infection vector, approaching unsuspecting developers on sites like LinkedIn and enticing them to download malicious packages under the guise of a skills test.

These packages are either published directly to public repositories such as npm or PyPI, or hosted in a GitHub repository that you control.

ReversingLabs says it has found malicious code embedded within modified versions of legitimate PyPI libraries, including pyperclip and pyrebase.

“The malicious code is present in both the __init__.py files and their corresponding compiled Python files (PYC) in the __pycache__ directory of each module,” Zanki said.

This is implemented in the form of a Base64 encoded string that hides the downloader functionality to establish a connection with a command and control (C2) server to execute commands received in response.

In one example coding challenge identified by a software supply chain company, threat actors sought to create a false sense of urgency by requiring job seekers to build a Python project shared in a ZIP file format within five minutes, and then find and fix a coding flaw within the next 15 minutes.

Fake coding tests

This “increases the likelihood of the packages being executed without any kind of security or source code review,” Zanke said, adding that “this gives the bad actors behind this campaign confidence that the embedded malware will be executed on the developer’s system.”

See also  A key ally in the fight against climate change? People over 60

Some of the aforementioned tests purported to be technical interviews for financial institutions such as Capital One and Rookery Capital Limited, highlighting threat actors conducting operations by impersonating legitimate companies in the industry.

It’s unclear at this point how widespread these campaigns are, but as Google-owned Mandiant recently revealed, they are also using LinkedIn to locate and contact potential targets.

“After the initial chat conversation, the attackers compromised the user’s macOS system by sending a ZIP file containing the COVERTCATCH malware disguised as a Python coding challenge and downloading second-stage malware that persists via a launch agent and launch daemon,” the company said.

The development comes after cybersecurity firm Genians revealed that a North Korean threat actor codenamed Konni has been stepping up attacks against Russia and South Korea using spear-phishing baits that have led to the deployment of AsyncRAT, which has been seen to overlap with a campaign codenamed CLOUD#REVERSER (aka puNK-002).

Some of these attacks also involve the distribution of a new malware called CURKON, a Windows shortcut (LNK) file that acts as a downloader for an AutoIt version of the Lilith RAT. According to S2W, this activity is associated with a subcluster being tracked as puNK-003.

Share This Article
Twitter Copy Link
Previous Article Wild Bastards Review - Stylish Wild West Roguelike FPS Wild Bastards Review – Stylish Wild West Roguelike FPS
Next Article Trump assassin suspect says he wanted to fight in Ukraine Trump assassin suspect says he wanted to fight in Ukraine
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

Google's AI Data Practices in Europe
Technology

Irish watchdog launches investigation into Google’s AI data practices in Europe

3 Min Read
Crypto Mining and Proxyjacking
Technology

Exposed Selenium Grid servers targeted for cryptomining and proxyjacking

3 Min Read
Justin Timberlake's DUI case: Inside the arrest, indictment, and guilty plea
Celebrity

Justin Timberlake’s DUI case: Inside the arrest, indictment, and guilty plea

4 Min Read
DPAD algorithm enhances brain-computer interfaces, promising advances in neurotechnology
Technology

DPAD algorithm enhances brain-computer interfaces, promising advances in neurotechnology

7 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?