Microsoft: Hackers go headhunting on LinkedIn, use WhatsApp to deliver malware | ZDNET

microsoft:-hackers-go-headhunting-on-linkedin,-use-whatsapp-to-deliver-malware-|-zdnet

Image: Natee Meepian / ShutterstockMicrosoft is warning that hackers are using open source software and bogus social media accounts to dupe software engineers and IT support staff with fake job offers that in reality lead to malware attacks.A phishing-happy hacking crew linked to North Korea’s armed forces has been using trojanized open-source apps and LinkedIn recruitment bait to hit tech industry employees, according to threat analysts from Microsoft’s advanced persistent threat (APT) research group.The Microsoft Threat Intelligence Center (MSTIC, pronounced ‘Mystic’) has seen the group using PuTTY, KiTTY, TightVNC, Sumatra PDF Reader, and the muPDF/Subliminal Recording software installer for these attack since late April, according to MSTIC’s blogpost. Also: The scary future of the internet: How the tech of tomorrow will pose even bigger cybersecurity threatsThe hacking group has targeted employees in media, defense and aerospace, and IT services in the US, UK, India, and Russia. The group was also behind the massive attack on Sony Pictures Entertainment in 2014.Also known as Lazarus, and tracked by Microsoft as ZINC, Google Cloud’s Mandiant threat analysts saw the group spear-phishing targets in the tech and media sectors with bogus job offers in July, using WhatsApp to share a trojanized instance of PuTTY.”Microsoft researchers have…
Read More

Exit mobile version