Threat actors connected to North Korea have been seen using LinkedIn to target developers as part of a fictitious employment recruitment scheme.
In a recent analysis about the vulnerabilities facing the Web3 sector, Google-owned Mandiant stated that these assaults use code exams as a frequent initial infection vector.
The attacker emailed a ZIP file with COVERTCATCH malware after they had a chat interaction, according to researchers Blas Kojusner, Joseph Dobson, and Robert Wallace. The file appeared to be a Python coding challenge.
Using Launch Agents and Launch Daemons to provide persistence, the second-stage payload that the virus downloads and installs on the target’s macOS system serves read more about North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
