Wu Shuo learned that security company SentinelOne released a report stating that researchers discovered a macOS backdoor program identical to that used in the earlier LayerZero attack event in an Indian IT services company that is not related to the encryption industry. The related attacks were attributed to TraderTraitor, a threat actor under the North Korean Lazarus hacking group, which previously participated in the attack that caused KelpDAO to lose $292 million. The report said the attackers targeted developers by conducting fake recruitment interviews and using GitHub projects that contained malicious code, prompting them to run malware. The newly discovered victim is a DevOps engineer; the backdoor on the victim’s device was first observed on March 18, but the specific infection vector has not yet been confirmed.
