Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware
In January 2024, the notorious threat actor Lazarus Group, associated with the Democratic People's Republic of Korea (DPRK), was seen using a "complex infection chain" to attack at least two employees of an unidentified nuclear-related company in a single month.
The attacks, which resulted in the installation of a new modular backdoor called CookiePlus, are a component of Operation Dream Job, a lengthy cyber espionage effort that antivirus firm Kaspersky also tracks as NukeSped. Since at least 2020, when ClearSky made it public, it has been known to be operational.
Targeting developers and workers in a variety of industries, such as defense, aerospace, cryptocurrency, and other international areas, with attractive employment possibilities that eventually lead to read more about Laza...

