North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams
By MYBRANDBOOK
A new wave of cyberattacks targeting organizations worldwide has emerged, with North Korean threat actors utilizing LinkedIn as a primary vector to deploy the sophisticated COVERTCATCH malware.
The threat groups, possibly linked to cyber-espionage campaigns. COVERTCATCH, a sophisticated malware designed for surveillance, data exfiltration, or other malicious purposes.
The malware is being distributed through job-related scams on LinkedIn, a professional networking platform. The attackers create fraudulent job postings on LinkedIn, often targeting specific industries or geographic regions. These postings typically feature enticing job titles and attractive salary offers.
Once the malware is executed, it begins to infiltrate the victim's system, stealing sensitive data such as login credentials, financial information, and intellectual property.
The described malware's method of attack—compromising macOS systems by downloading a second-stage payload and establishing persistence through Launch Agents and Launch Daemons—is a crucial element in the broader set of cyber-espionage campaigns linked to North Korean hacking groups. These groups, often associated with Lazarus Group or APT38, employ a consistent and highly-targeted approach, using job-related decoys to lure victims into downloading malicious files.
Recruiting-themed lures have become a common tactic employed by cybercriminals, including North Korean threat actors, to distribute malware such as RustBucket and KANDYKORN. These campaigns typically involve job-related decoys, where attackers pose as recruiters and send malicious documents or links to potential victims under the guise of job opportunities.
COVERTCATCH is capable of exfiltrating large amounts of data from compromised systems, potentially causing significant financial and reputational damage to targeted organizations. The malware is designed to remain undetected on infected systems for extended periods, allowing attackers to maintain persistent access and launch further attacks.
By understanding the tactics used by North Korean threat actors and taking proactive steps to prevent malware infections, organizations can significantly reduce their risk of falling victim to these sophisticated cyberattacks.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
EXIDE INDUSTRIES LTD.
MICROTEK INTERNATIONAL PVT. LTD.
BEETEL TELETECH LTD.
TP-LINK INDIA PVT. LTD.
Icons Of India : Dr. Arvind Gupta
Arvind Gupta is the Head and Co-Founder of the Digital India Foundatio...
Icons Of India : AALOK KUMAR
Aalok Kumar is celebrated as a global leader and recipient of the Peop...
ICONS OF INDIA : RAMESH NATRAJAN
Ramesh Natarajan, CEO of Redington Limited, on overcoming ‘technolog...
STPI - Software Technology Parks of India
STPI promotes and facilitates the growth of the IT and ITES industry i...
CSC - Common Service Centres
CSC initiative in India is a strategic cornerstone of the Digital Indi...
GeM - Government e Marketplace
GeM is to facilitate the procurement of goods and services by various ...
Indian Tech Talent Excelling The Tech World - NEAL MOHAN, CEO - Youtube
Neal Mohan, the CEO of YouTube, has a bold vision for the platform’s...
Indian Tech Talent Excelling The Tech World - Dheeraj Pandey, CEO, DevRev
Dheeraj Pandey, Co-founder and CEO at DevRev , has a remarkable journe...
Indian Tech Talent Excelling The Tech World - Rajiv Ramaswami, President & CEO, Nutanix Technologies
Rajiv Ramaswami, President and CEO of Nutanix, brings over 30 years of...