State-sponsored hackers exploit zero-day vulnerabilities to target security researchers

1 min read
Source: BleepingComputer
State-sponsored hackers exploit zero-day vulnerabilities to target security researchers
Photo: BleepingComputer
TL;DR Summary

Google's Threat Analysis Group (TAG) has reported that state-sponsored hackers from North Korea are targeting security researchers using at least one zero-day exploit in an undisclosed popular software. The attackers use social media platforms like Twitter and Mastodon to establish contact with the researchers and then send them malicious files designed to exploit the zero-day. The payload collects information from the researchers' systems and sends it to the attackers' command and control servers. This campaign is similar to previous attacks in January 2021, indicating the involvement of the Lazarus Group. The primary objective of these attacks appears to be the acquisition of undisclosed security vulnerabilities and exploits.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

78%

476107 words

Want the full story? Read the original article

Read on BleepingComputer