Threat Advisory

Lazarus Hackers Distribute Linux Malware Through Deceptive Job Offers

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Security researchers have recently detected a new campaign by the Lazarus group, known as "Operation DreamJob," which marks the first time that the group has targeted Linux users with malware. ESET's researchers have discovered that Lazarus, in a new campaign named "Operation DreamJob," is targeting Linux users with malware for the first time. Researchers from ESET have discovered Lazarus targeting Linux users with malware for the first time, which further supports the hypothesis that the group was behind the recent supply-chain attack on VoIP provider 3CX. The detailed information regarding supply-chain attack on VOIP provider 3CX is given in the references below. Prior to this discovery, it was suspected that Lazarus was behind the attack on VoIP provider 3CX, and multiple cybersecurity companies had concluded with high confidence that the attackers responsible for the trojanization of 3CX were linked to North Korea. The ongoing operation, known as Operation DreamJob or Nukesped, is part of Lazarus' modus operandi, which involves targeting professionals working in software or DeFi platforms by presenting them with false job offers via LinkedIn and other social media and communication channels.[/subscribe_to_unlock_form]

Summary:

Security researchers have recently detected a new campaign by the Lazarus group, known as "Operation DreamJob," which marks the first time that the group has targeted Linux users with malware. ESET's researchers have discovered that Lazarus, in a new campaign named "Operation DreamJob," is targeting Linux users with malware for the first time. Researchers from ESET have discovered Lazarus targeting Linux users with malware for the first time, which further supports the hypothesis that the group was behind the recent supply-chain attack on VoIP provider 3CX. The detailed information regarding supply-chain attack on VOIP provider 3CX is given in the references below. Prior to this discovery, it was suspected that Lazarus was behind the attack on VoIP provider 3CX, and multiple cybersecurity companies had concluded with high confidence that the attackers responsible for the trojanization of 3CX were linked to North Korea. The ongoing operation, known as Operation DreamJob or Nukesped, is part of Lazarus' modus operandi, which involves targeting professionals working in software or DeFi platforms by presenting them with false job offers via LinkedIn and other social media and communication channels.[emaillocker id="1283"]

The attackers employ social engineering tactics to deceive their victims into downloading malicious files that are disguised as documents containing information about the fake job offer. The documents provided by the attackers are actually a way for them to inject malware onto the victim's computer. Lazarus was found to be distributing a malicious ZIP archive via spear phishing or direct messages on LinkedIn. The archive contains a Linux binary written in Go, disguised as a PDF by using a Unicode character in its name. The filename does not have the .pdf file extension, as it uses a Unicode character, U+2024, that appears like a dot to make the filename look like it ends with .pdf. The intention behind using the leader dot in the filename was likely to deceive the file manager into treating the file as an executable rather than a PDF.

Execution Flow of Lazarus’s latest attack against Linux Targets

Upon double-clicking the file, the malware named "OdicLoader" presents a fake PDF to deceive the recipient while secretly downloading a second-stage malware payload from a private repository on the OpenDrive cloud service. After displaying the decoy PDF, the malware "OdicLoader" downloads a second-stage payload from a private repository hosted on the OpenDrive cloud service. This payload, known as "SimplexTea," is a C++ backdoor that is dropped at "~/.config/". To ensure SimplexTea is launched with Bash and its output is muted when a user starts a new shell session, OdicLoader modifies the user's ~/.bash_profile.

After analyzing SimplexTea, researchers discovered that it shares many similarities with other malware such as BadCall and SimpleSea in terms of functionality, encryption techniques, and hardcoded infrastructure. A previous variant of the SimplexTea malware called "sysnetd" was found on VirusTotal, written in C and similar in functionality, encryption techniques, and infrastructure used by the Lazarus group's "BadCall" Windows malware and "SimpleSea" macOS variant. Although the XOR key used by the SimplexTea and SimpleSea payloads is different, it was discovered that the configuration file they use shares the same name.

Lazarus' adoption of Linux malware and the 3CX attack demonstrate their ability to adapt and evolve their tactics, expanding their targets to encompass all major operating systems such as Windows, macOS, and Linux. The recent supply-chain attack on 3CX by Lazarus represents another significant achievement for the notorious cybercrime group.

Threat Profile:

References:

The following reports contain further technical details:

https://Eventus Security.com/advisory/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/

https://www.bleepingcomputer.com/news/security/lazarus-hackers-now-push-linux-malware-via-fake-job-offers/

[/emaillocker]
crossmenu