Kaspersky discovers Lazarus APT targets nuclear organizations with new CookiePlus malware

Lazarus’ key operation – “Operation DreamJob” – continues to evolve with new sophisticated tactics that have persisted for more than five years, according to Kaspersky’s Global Research and Analysis Team (GReAT). The latest targets include employees from a nuclear-related organization, who were infected via three compromised archive files appearing to be skill assessment tests for IT professionals. This ongoing campaign leverages a range of advanced malware, including a newly discovered modular backdoor, CookiePlus, that was disguised as open-source plugin.
Kaspersky’s GReAT discovered a new campaign linked to the infamous Operation DreamJob, also known as DeathNote, a cluster associated with the notorious Lazarus group. Over the years, this campaign has evolved significantly, initially emerging in 2019, with attacks targeting worldwide cryptocurrency-related businesses. During 2024, it has expanded to target IT and defense companies across Europe, Latin America, South Korea, and Africa. Kaspersky’s latest report provides new insights into a recent phase of their activity, revealing campaign targeting employees working at the same nuclear-related organization in Brazil as well employees of an unidentified sector in Vietnam.
Over the span of one month, at least two employees from the same organization were targeted by Lazarus, receiving multiple archive files disguised as skill assessments for IT positions at prominent aerospace and defense companies. Lazarus initially delivered the first archive to Hosts A and B within the same organization, and after a month, attempted more aggressive attacks on the first target. They likely used job search platforms like LinkedIn to deliver the initial instructions and gain access to the targets.
Lazarus has evolved its delivery methods and improved persistence through a complex infection chain involving various types of malware, such as a downloader, loader, and backdoor. They launched a multi-stage attack using trojanized VNC software, a remote desktop viewer for Windows, and another legitimate VNC tool to deliver malware. The first stage involved a trojanized AmazonVNC.exe, which decrypted and executed a downloader called Ranid Downloader to extract internal resources of the VNC executable. A second archive contained a malicious vnclang.dll that loaded MISTPEN malware, which then fetched additional payloads, including RollMid and a new variant of LPEClient.

Route of malicious files created on victims host
Additionally, they deployed an unseen plugin-based backdoor which GReAT experts dubbed CookiePlus. It was disguised as ComparePlus, an open-source Notepad++ plugin. Once established, the malware collects system data, including the computer name, process ID, and file paths, and makes its main module “sleep” for a set amount of time. It also adjusts its execution schedule by modifying a configuration file.
“There are substantial risks including data theft, as Operation DreamJob gathers sensitive system information that could be used for identity theft or espionage. The malware’s ability to delay its actions allows it to evade detection at the moment of penetration and persist longer on the system. By setting specific execution times, it can operate at intervals that might avoid being noticed. Additionally, the malware could manipulate system processes, making it harder to detect and potentially leading to further harm or exploitation of the system,” comments Sojun Ryu, security expert at Kaspersky’s Global Research and Analysis Team.
Learn more about new Lazarus campaign at Securelist.com.

Related Posts

Małopolska Tourism CEO Welcomes Etihad Airways’ Decision to Launch Direct Flights from Abu Dhabi to Kraków

HYGGE HOTEL – A HOME OF HAPPINESS AT THE HEART OF EUROPE

Dubai Tops Global Charts with 140 Branded Projects Set for Delivery by 2031

Inside FunkSec: Kaspersky explores the evolution of AI-powered ransomware with password-gated capabilities

The domain of deception: Attackers deploy spyware under the guise of legal threats

Thndr Recognized by World Economic Forum as 2025Technology Pioneer The only Egyptian and North African company among the 2025

British Council’s Deep Dialogues Brings Together Delegates from Egypt, Tunisia and Saudi Arabia in Cardiff

Commvault Convenes Egypt’s Cybersecurity Leaders at SHIFT Cairo

آخر الأخبار
الهواتف الذكية "داريا بوند" و "داريا بوند 2 " تستقطب العملاء في دول مجلس التعاون الخليجي "جيمس للتعليم" تحتفي بتحقيق طلاب البكالوريا الدولية نتائج متميزة وزير الصناعة يزور مصنع مارس مصر في جولة هي الأولى من نوعها لتعزيز التعاون الصناعي اتصالات مكثفة لوزير الخارجية والهجرة لتثبيت وقف إطلاق النار بين إيران وإسرائيل وزير المالية: التباحث حول زيادة التمويل المشترك لمشروعات البنية التحتية والطاقة وتنسيق السياسات الإن... وزير العمل يوجه بمتابعة تداعيات حادث المنوفية.. ويتقدم بالعزاء لأسرة المتوفين.. وبسرعة الشفاء للمصاب... كايروكى يختتم حفلات مهرجان العلمين الجديدة 29 أغسطس وزير الصناعة والنقل يفتتح خط إنتاج مرشحات الغسيل الكلوي ومصنع محاليل الغسيل الكلوي بطاقة ٤٠ مليون لت... وزير الإسكان ومحافظ بني سويف يتابعان موقف المشروعات التنموية بمدينة بني سويف الجديدة وزيرة التضامن تتابع تداعيات حادث الطريق الإقليمى.. وتوجه بتقديم الدعم لأسر الضحايا «آي صاغة»: الذهب يحقق مكاسب أسبوعية تتجاوز 1.9%.. وتصريحات ترامب التجارية تدعم الأسعار عالميًا وزير قطاع الأعمال في جولة ميدانية بشركة دمياط للغزل والنسيج لمتابعة تقدم العمل بمشروع التطوير المملكة والعراق والإمارات والكويت وكازاخستان والزائر وسلطنة عمان أكدوا مجددًا التزامهم باستقرار البت... وزير الصحة يتابع تداعيات حادث الطريق الإقليمي بالمنوفية ويوجه بتقديم كافة أوجه الدعم للمصابين وأهال... أحمد شريف : الاتفاق الأوروبي الأميركي المرتقب سيعيد رسم خارطة الاقتصاد العالمي "التعليم العالي" تعلن تفاصيل اختبارات القدرات المؤهلة للالتحاق ببعض الكليات "الزراعة" تطلق 214 قافلة بيطرية مجانية في 176 قرية خلال يونيو الماضي «AlSultan Hyper Egypt» تعلن قرب افتتاح فرع جديد لـ«هايبر ماركت السلطان-أقل سعر» في حدائق أكتوبر وزير قطاع الأعمال العام يبدأ زيارة تفقدية لشركة دمياط للغزل والنسيج ويلتقي عددا من نواب البرلمان المملكة تحقق المركز الأول من بين 164 دولة في مؤشر تنمية الاتصالات والتقنية لعام 2025