According to OpenSourceMalware research, North Korean hacking group Lazarus hid second-stage loaders in Git Hooks pre-commit scripts during developer-targeting attacks on May 9. The group used the technique in campaigns including ‘Infectious Interview,’ where it posed as cryptocurrency and DeFi recruiters to trick developers into cloning malicious code repositories, ultimately aiming to steal crypto assets and credentials.
Related News
Chaos Labs discloses it was attacked by a "state-sponsored actor," and Oracle network confirms it was not compromised
Education platform Canvas confirms it was hacked; 275 million users’ personal data may be leaked
SlowMist alert: SlowMist alert—High-risk privilege escalation vulnerability in Linux—disable three modules as an emergency mitigation