Lazarus Group Targets Web3 Developers with Fake LinkedIn Profiles in Operation 99
The Lazarus Group, which has ties to North Korea, has been implicated in Operation 99, a recent cyberattack campaign that targeted software engineers seeking freelancing Web3 and cryptocurrency employment in order to distribute malware.
In a new research released today, Ryan Sherstobitoff, senior vice president of Threat Research and Intelligence at SecurityScorecard, stated, "The campaign starts with fake recruiters, posing on platforms like LinkedIn, luring developers with project tests and code reviews."
After falling for the trick, a victim is taken to clone a malicious GitLab repository, which appears to be innocuous but is actually full of catastrophes. By connecting to command-and-control (C2) servers, the cloned code introduces malware into the victim's surroundings read mor...

