Skip to main content
عربي
logo

NCSC-TAD-2509-001

Severity Level: Low
Phishing

Reference No.: NCSC-TAD-2509-001CVSS 0

Lazarus Group LinkdIn Campaign

Threat Type:
N/A
TLP:
CLEAR
CVE:
N/A

Overview

An ongoing sophisticated recruiting scam campaign attributed to the Lazarus Group, leveraging fake LinkdIn job offers to target organizations.

The campaign involves impersonating legitimate recruiters to deliver documents that establish persistence and exfiltrate sensitive information.

Mitigation and Immediate Actions

  1. 01

    Educate users on social engineering and spear-phishing attacks.

  2. 02

    Restrict macro execution and untrusted file types.

  3. 03

    Monitor for unusual network activity and anomalous C2 communications.

References