الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky discovers Lazarus APT targets nuclear organizations with new CookiePlus malware

Lazarus’ key operation – “Operation DreamJob” – continues to evolve with new sophisticated tactics that have persisted for more than five years, according to Kaspersky’s Global Research and Analysis Team (GReAT). The latest targets include employees from a nuclear-related organization, who were infected via three compromised archive files appearing to be skill assessment tests for IT professionals. This ongoing campaign leverages a range of advanced malware, including a newly discovered modular backdoor, CookiePlus, that was disguised as open-source plugin.
Kaspersky’s GReAT discovered a new campaign linked to the infamous Operation DreamJob, also known as DeathNote, a cluster associated with the notorious Lazarus group. Over the years, this campaign has evolved significantly, initially emerging in 2019, with attacks targeting worldwide cryptocurrency-related businesses. During 2024, it has expanded to target IT and defense companies across Europe, Latin America, South Korea, and Africa. Kaspersky’s latest report provides new insights into a recent phase of their activity, revealing campaign targeting employees working at the same nuclear-related organization in Brazil as well employees of an unidentified sector in Vietnam.
Over the span of one month, at least two employees from the same organization were targeted by Lazarus, receiving multiple archive files disguised as skill assessments for IT positions at prominent aerospace and defense companies. Lazarus initially delivered the first archive to Hosts A and B within the same organization, and after a month, attempted more aggressive attacks on the first target. They likely used job search platforms like LinkedIn to deliver the initial instructions and gain access to the targets.
Lazarus has evolved its delivery methods and improved persistence through a complex infection chain involving various types of malware, such as a downloader, loader, and backdoor. They launched a multi-stage attack using trojanized VNC software, a remote desktop viewer for Windows, and another legitimate VNC tool to deliver malware. The first stage involved a trojanized AmazonVNC.exe, which decrypted and executed a downloader called Ranid Downloader to extract internal resources of the VNC executable. A second archive contained a malicious vnclang.dll that loaded MISTPEN malware, which then fetched additional payloads, including RollMid and a new variant of LPEClient.

Route of malicious files created on victims host
Additionally, they deployed an unseen plugin-based backdoor which GReAT experts dubbed CookiePlus. It was disguised as ComparePlus, an open-source Notepad++ plugin. Once established, the malware collects system data, including the computer name, process ID, and file paths, and makes its main module “sleep” for a set amount of time. It also adjusts its execution schedule by modifying a configuration file.
“There are substantial risks including data theft, as Operation DreamJob gathers sensitive system information that could be used for identity theft or espionage. The malware’s ability to delay its actions allows it to evade detection at the moment of penetration and persist longer on the system. By setting specific execution times, it can operate at intervals that might avoid being noticed. Additionally, the malware could manipulate system processes, making it harder to detect and potentially leading to further harm or exploitation of the system,” comments Sojun Ryu, security expert at Kaspersky’s Global Research and Analysis Team.
Learn more about new Lazarus campaign at Securelist.com.

Related Posts

bp Announces Successful Completion of Drilling of “El King-2” Exploration Well

Navigating transformative regional and local developments: PwC Middle East announces Egypt’s 2025 Annual Tax and Legal Seminar

cardoO Enhances the VR Experience with the Launch of the Innovative cardoO VR

UNDER THE PATRONAGE OF HIS ROYAL HIGHNESS THE CROWN PRINCE, SAUDI ARABIA ANNOUNCES THE SECOND EDITION OF THE HUMAN CAPABILITY INITIATIVE CONFERENCE (HCI 2025) THIS UPCOMING APRIL

Valu and GoodsMart Announce Partnership to Introduce Flexible Payment Solutions to Household Purchases

Madinet Masr and e& Egypt Ink a Strategic Partnership to Sponsor G.Talks

Fawry Signs Strategic Partnership with PharmaOverseas to Enhance Digital Transformation in The Pharmaceutical Sector

FABMISR Net Profit Surges by 153% Reaching EGP 26.3 Billion at the End of 2024

آخر الأخبار
وزير النقل: قريبا إنتاج الحديد المستخدم فى صناعة السفن محليا الرئيس السيسي يشدد على سرعة إعادة إعمار غزة وبدء عملية سياسية لحل الدولتين التجارى وفا بنك إيجيبت يفتتح فرعه الجديد بميدان التحرير رئيس هيئة الدواء المصرية يستقبل ممثلي شركة أسبن الدولية وزير العمل ومحافظ الفيوم يسلمان عقود لذوي همم.. وشهادات لخريجي دورات تدريب مهني تعيين خالد صلاح نائبا للرئيس التنفيذي للأخبار والصحف لشئون التحول الرقمي بالشركة المتحدة شادي الكومي: نرفض تهجير الفلسطينيين من غزة ونؤكد دعمنا لحقوقهم المشروعة «آي صاغة»: الحرب التجارية الثانية قد تدفع لركود تضخمي البورصة المصرية تبحث تعزيز سيولة السوق بالتعاون مع البنك الأوروبي لإعادة الإعمار والتنمية (EBRD) شراكة بين مؤسسة التمويل الدولية وبنك CIB لدعم جهود الحد من الانبعاثات الكربونية بالقطاعات الرئيسية ف... وزير السياحة والآثار يعقد مؤتمراً صحفياً حضره العديد من ممثلي وسائل الإعلام التركية ولقاءات إعلامية OPPO تواصل تعاونها مع هيئة تنشيط السياحة لرعاية مسابقة imagine IF رئيس اقتصادية قناة السويس يلتقي مسؤولي تويوتا تسوشو لمناقشة تطورات محطة الرورو بميناء شرق بورسعيد الاتحاد المصري للتأمين يعقد ورشة عمل حول " المخاطر المؤسسية بين النظرية والتطبيق " "انطلاق النسخة الثالثة لتحدي مصر للتكنولوجيا المالية" بنك مصر يوقع عقد حساب وسيط مع كلاً من 6 أكتوبر للتنمية والاستثمار (سوديك) وشركة الصافى للتطوير العقا... وزيرة التنمية المحلية تبحث مع سفيرة البحرين بالقاهرة مجالات التعاون المشترك بين البلدين مصر للطيران تحتفل بمرور 70عامًا على تأسيس (الكرنك للسياحة) ريال مدريد يستضيف أتلتيكو في ديربي ناري يتوقع العديد من الاتحامات القوية، البطاقات الملونة، واللحظات... ختام أعمال ورشة عمل تحديات ومتطلبات التطبيق العملي للمعيار الدولي للتقارير المالية IFRS 9