Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

TC starts all stages in Boston, six days until the end of savings up to $475

Samsung launches Z Fold7 and Z Flip7 and adds a cheap Z Flip7 Fe ​​to its collapsible lineup

donot apt expands operations and targets the European Ministry of Foreign Affairs with lopticmod malware

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Lazarus Group deploys MarStech1 JavaScript implants to target developer attacks
Identity

Lazarus Group deploys MarStech1 JavaScript implants to target developer attacks

userBy userFebruary 14, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 14, 2025Ravi LakshmananBrowser Security/Cryptocurrency

JavaScript Implants

The North Korean threat actor known as the Lazarus Group was named a previously undocumented JavaScript implant as part of a limited targeted attack on the developer.

The active operation is called Marstech Mayhem by SecurityScorecard and malware is delivered by an open source repository hosted on GitHub, which is associated with a profile named “Successfriend.” Active profiles are no longer accessible on the code hosting platform since July 2024.

Implants are designed to collect system information and are embedded in websites and NPM packages, pose supply chain risks. The first appearance of malware in late December 2024 shows evidence. The attack has accumulated 233 confirmed victims across the US, Europe and Asia.

Cybersecurity

“The profile mentioned web development skills and learning blockchain that are aligned to Lazarus’ interests,” SecurityScorecard said. “The threat actors were pre-confused by various GitHub repositories and committed both obfuscated payloads.”

With an interesting twist, it is known that the implants present in the GitHub repository are different from the versions provided directly from the 74.119.194 command and control (C2) server.[.]129:3000/j/marstech1. It indicates that it may be under active development.

Its main responsibility is to search across Chromium-based browser directories for various operating systems and modify the extended-related settings, particularly related to Metamask cryptocurrency wallets. You can also download additional payloads from the same server on port 3001.

Other wallets targeted by malware include Exodus and Atoms above the window, Linux, and macO. Captured data will be extended to C2 endpoint “74.119.194[.]129:3000/Uploaded. ”

“Introduction of MarStech1 implants with layered obfuscation techniques – from flattening control flow to renaming dynamic variables in JavaScript to multi-stage XOR decoding in Python – provides both static and dynamic analysis. It highlights the sophisticated approach of threat actors to avoid it.”

This disclosure is part of the October-November 2024 contagious interview campaign, with at least three organizations in the broader cryptocurrency space, market establishment companies, online casinos and software development companies. It was revealed that he was targeted as a

Cybersecurity

The cybersecurity company tracks the cluster under the name Purplebravo, saying that North Korean IT workers behind the fraudulent employment scheme are behind the threat of cyber espionage. It is also tracked under the name CL-STA-0240, the famous Chorima and tenacious Punsan.

“Organisations that unconsciously hire No-Con South Korean IT workers are violating international sanctions and may be exposed to legal and financial impacts,” the company said. “More importantly, these workers will almost certainly act as insider threats, stealing their own information, promoting backdoor introductions, or greater cyber operations.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDo AI and automatic planes help prevent plane collisions? |Air News
Next Article New “Fuami” attacks cause ami name confusion for remote code execution
user
  • Website

Related Posts

donot apt expands operations and targets the European Ministry of Foreign Affairs with lopticmod malware

July 9, 2025

North Korea Andariel Hacker Behind US Sanctions Fraudulent IT Worker Scheme

July 9, 2025

How to automate ticket creation, device identification, and threat triage with tines

July 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

TC starts all stages in Boston, six days until the end of savings up to $475

Samsung launches Z Fold7 and Z Flip7 and adds a cheap Z Flip7 Fe ​​to its collapsible lineup

donot apt expands operations and targets the European Ministry of Foreign Affairs with lopticmod malware

EDF confirms 12.5% ​​shares in Sizewell c

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Robots Play Football in Beijing: A Glimpse into China’s Ambitious AI Future

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.