Beware: Counterfeit Skills Assessment Platforms Exploiting IT Job Hunters, Microsoft Alerts
A faction within the well-known Lazarus Group, identified as Sapphire Sleet (also known as APT38, BlueNoroff, CageyChameleon, and CryptoCore), has recently established deceptive infrastructure mimicking skills assessment portals. Microsoft, which detected this activity, notes it as a notable shift in the persistent actor's tactics.
Sapphire Sleet has a history of orchestrating cryptocurrency theft through social engineering. The group often targets individuals on platforms like LinkedIn using skills assessment-related lures, subsequently transitioning successful communications to other platforms.
Microsoft reveals that the hackers previously relied on tactics such as sending malicious attachments or embedding links in legitimate websites like GitHub. However, the prompt identification and removal of these payloads may have prompted Sapphire Sleet to create its network of websites for malware distribution, using password protection to hinder analysis.
In a related development, Jamf Threat Labs connected the threat actor to a new macOS malware family called ObjCShellz, considered a late-stage payload associated with another macOS malware known as RustBucket.
Source: https://thehackernews.com/2023/11/microsoft-warns-of-fake-skills.html