lastweek.lazarus.day

LW22: Developer lures, stolen build access, and persistent control

Executive Summary

Last week’s reports kept developers and cryptocurrency organizations at the center of DPRK-linked activity. Fake recruiting, malicious editor tasks, compromised package branches, npm payloads, fake conferencing updates, and stolen development credentials all created paths from a single workstation into code distribution and financial systems.

Kimsuky and TA406 continued to pair tailored phishing with scripts, newly disclosed vulnerabilities, legitimate cloud services, and remote-access tooling. RemotePE supplied a separate model for long-lived access in finance, while broader reporting connected developer compromise to DeFi theft and supply chain operations. One infrastructure observation inside DPRK address space remained exploratory rather than a confirmed intrusion campaign.

1. Developer lures crossed package and editor boundaries

A smart-contract security developer received a fake recruiting email that led to a GitLab repository whose VS Code task installed a malicious extension and native Go implants.1 A compromised Packagist development branch used a JavaScript loader and multi-blockchain dead drop in a likely Famous Chollima coding-task lure.2 SafeDep’s MicrosoftSystem64 analysis found a cross-platform npm RAT that stole browser, wallet, Telegram, SSH, clipboard, and screen data while using Hugging Face for exfiltration.3

Sapphire Sleet used a fake Zoom SDK update against macOS users in venture capital, Web3, and cryptocurrency organizations, followed by password prompts, TCC abuse, LaunchDaemon persistence, and an in-memory beacon.4 Across these cases, ordinary developer and meeting workflows provided the execution path.

2. Stolen development access enabled downstream compromise

Wiz tracked JINX-0164 using recruiter lures and AUDIOFIX to steal wallet, cloud, GitHub, and CI/CD secrets before compromising software distribution and trojanizing @velora-dex/sdk.5 A separate analysis described the same cluster as North Korea-linked, but the original Wiz assessment found behavioral similarities without infrastructure overlap and did not attribute it to a state sponsor.6 The stronger conclusion is that JINX-0164 poses a directly relevant adjacent threat to the same cryptocurrency development environment.

RemotePE showed how Lazarus-linked access could persist after entry through memory-only execution, encrypted C2, plugin loading, and EDR evasion.7 A monthly incident review placed these techniques beside the Drift Protocol and KelpDAO thefts and the Axios supply chain compromise.8 ESET’s multi-month review likewise covered the Axios intrusion, developer targeting, cryptocurrency operations, and activity by Andariel and ScarCruft.9

3. Kimsuky and TA406 reused phishing foundations with newer components

Proofpoint observed TA406 chaining two Office and Windows vulnerabilities in diplomatic-themed RTF lures before retrieving and executing a DLL payload.10 ENKI published English and Korean analyses of Kimsuky campaigns that used fake security software and Webex pages, JSONPing localhost checks, and a new in-memory HttpSpy variant.1112

A card-company secure-mail lure used LNK, PowerShell, mshta, obfuscated VBScript, Google Drive, and payloads for backdoor access and information theft.13 AhnLab’s April review placed similar LNK and script chains across South Korea-focused spear-phishing activity.14 Hauri’s KimjongRAT variant added Telegram and Discord collection and installed a MeshCentral agent, shifting the chain toward persistent remote control.15

4. Infrastructure labels can hide wider campaign roles

An investigation of a server first labeled as FTP infrastructure later connected it to OtterCookie-related collection, a reminder that one observed service may reveal only part of a campaign host’s purpose.16 Separately, NK Internet observed a captive portal framework under test in DPRK IP space, including connectivity checks, Korean comments, and a Huawei-themed WiFi error page.17

The captive portal finding supports monitoring, but it does not by itself establish a deployed phishing or access operation. Infrastructure purpose should be revised as new services and traffic become visible.

What to Watch

Treat repositories, package branches, editor tasks, conferencing updates, and development credentials as a connected attack surface. For Kimsuky and TA406 activity, correlate document and LNK delivery with localhost callbacks, script interpreters, cloud-hosted payloads, scheduled tasks, and newly installed remote-management agents.

Reports Reviewed