North Korean hacker collective Lazarus Group is using a new, highly sophisticated malware strain called LightlessCan in its recruitment fraud schemes. ESET senior malware researcher Peter Kálnai announced these findings after analysis of a fake job attack against a Spanish aviation company on September 29.
LightlessCan offers a significant improvement over its predecessor, BlindingCan. Kálnai explained that LightlessCan can emulate various native Windows commands, enabling stealth execution within a Remote Access Trojan (RAT).
This enhanced privacy means that EDRs, which are real-time monitoring solutions, and subsequently digital forensic tools, have difficulty detecting.
The new malware contains "execution protection rails" that ensure only the targeted victim's machine can decrypt the payload, preventing security researchers from unintended decryption.
The main purpose of Lazarus Group's attack on the Spanish aviation company was cyber espionage.
In particular, North Korean hackers are estimated to have stolen approximately $3.5 billion from cryptocurrency projects since 2016. This was reported by blockchain forensic analysis firm Chainalysis on September 14.
In September 2022, cybersecurity company SentinelOne issued a warning about fake job scams on LinkedIn. This was part of a campaign called "Operation Dream Job" and offered potential victims positions on Crypto.com.
At the same time, the United Nations is actively working to limit North Korea's cybercrime tactics internationally. The stolen funds are believed to have been used to support North Korea's nuclear missile program.
This ongoing effort highlights the global impact and consequences of cyberattacks by groups like Lazarus.
LightlessCan offers a significant improvement over its predecessor, BlindingCan. Kálnai explained that LightlessCan can emulate various native Windows commands, enabling stealth execution within a Remote Access Trojan (RAT).
This enhanced privacy means that EDRs, which are real-time monitoring solutions, and subsequently digital forensic tools, have difficulty detecting.
The new malware contains "execution protection rails" that ensure only the targeted victim's machine can decrypt the payload, preventing security researchers from unintended decryption.
The main purpose of Lazarus Group's attack on the Spanish aviation company was cyber espionage.
In particular, North Korean hackers are estimated to have stolen approximately $3.5 billion from cryptocurrency projects since 2016. This was reported by blockchain forensic analysis firm Chainalysis on September 14.
In September 2022, cybersecurity company SentinelOne issued a warning about fake job scams on LinkedIn. This was part of a campaign called "Operation Dream Job" and offered potential victims positions on Crypto.com.
At the same time, the United Nations is actively working to limit North Korea's cybercrime tactics internationally. The stolen funds are believed to have been used to support North Korea's nuclear missile program.
This ongoing effort highlights the global impact and consequences of cyberattacks by groups like Lazarus.