- Lazarus was seen poisoning open source -software with infostealers
- The campaign is called Phantom Circuit and targets mostly European software -Devs
- More stocks were found poisoned with malware
The notorious North Korean hackers Lazarus have been targeting software developers, especially those in the web3 industry, with infoStealing malware that grabbed their credentials, approval token and other valuable data, experts have warned.
CyberSecurity Research’s SecurityScorecard released a report describing the campaign that included a software supply chain attack and open source poisoning.
Lazarus Group, a notorious hacking collective on North Korea’s payroll, was discovered that various open source tools grabbed them, with malicious code and then returned them to code designs and platforms like Gitlab.
Targeting Web3 -Devs
Developers would then pick up these tools by mistake and would unconsciously be infected with malware.
The researchers appointed Operation Phantom Circuit and apparently ended up compromising more than 1,500 victims. Most of them are based in Europe with remarkable additions from India and Brazil.
The changed storage sites apparently included Codementor, Coinproperty, Web3 E-Store, a Python-based password managers and “other cryptocurrency-related apps, approval packages and web3 technologies”, with reference to Ryan Sherstobitoff, Senior VP for Research and Threat Intelligence.
The researchers did not say if Lazarus used any known infoTeals in this campaign or created new code from scratch. The group is known for using a wide range of tools in their attacks.
Lazarus is often targeted at cryptocurrency companies. Some researchers say the country participates in cryptot theft to finance its state apparatus as well as its weapons program. The group is famous for its fake job campaign, called Operation Dreamjob, where it is aimed at web3 software developers with fake, lucrative job offers.
In the interview phase, attacking the fool of the candidate to download and run Infostealers, seize their tokens and their employers. In such a case, Lazarus managed to steal approx. 600 million dollars.