https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/
الثلاثاء, 22 سبتمبر, 2026
سياسة الخصوصية
من نجن
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English
Techno fin
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English

A cyberattack targets nuclear organizations

by تكنو فن
ديسمبر 24, 2024
Reading Time: 3 mins read
A A
cyberattack

cyberattack

 

Lazarus’ key operation – “Operation DreamJob” – continues to evolve with new sophisticated tactics that have persisted for more than five years, according to Kaspersky’s Global Research and Analysis Team (GReAT). The latest targets include employees from a nuclear-related organization, who were infected via three compromised archive files appearing to be skill assessment tests for IT professionals. This ongoing campaign leverages a range of advanced malware, including a newly discovered modular backdoor, CookiePlus, that was disguised as open-source plugin.

Kaspersky’s GReAT discovered a new campaign linked to the infamous Operation DreamJob, also known as DeathNote, a cluster associated with the notorious Lazarus group. Over the years, this campaign has evolved significantly, initially emerging in 2019, with attacks targeting worldwide cryptocurrency-related businesses. During 2024, it has expanded to target IT and defense companies across Europe, Latin America, South Korea, and Africa. Kaspersky’s latest report provides new insights into a recent phase of their activity, revealing campaign targeting employees working at the same nuclear-related organization in Brazil as well employees of an unidentified sector in Vietnam.

Over the span of one month, at least two employees from the same organization were targeted by Lazarus, receiving multiple archive files disguised as skill assessments for IT positions at prominent aerospace and defense companies. Lazarus initially delivered the first archive to Hosts A and B within the same organization, and after a month, attempted more aggressive attacks on the first target. They likely used job search platforms like LinkedIn to deliver the initial instructions and gain access to the targets.

Lazarus has evolved its delivery methods and improved persistence through a complex infection chain involving various types of malware, such as a downloader, loader, and backdoor. They launched a multi-stage attack using trojanized VNC software, a remote desktop viewer for Windows, and another legitimate VNC tool to deliver malware. The first stage involved a trojanized AmazonVNC.exe, which decrypted and executed a downloader called Ranid Downloader to extract internal resources of the VNC executable. A second archive contained a malicious vnclang.dll that loaded MISTPEN malware, which then fetched additional payloads, including RollMid and a new variant of LPEClient.

Additionally, they deployed an unseen plugin-based backdoor which GReAT experts dubbed CookiePlus.  It was disguised as ComparePlus, an open-source Notepad++ plugin. Once established, the malware collects system data, including the computer name, process ID, and file paths, and makes its main module “sleep” for a set amount of time. It also adjusts its execution schedule by modifying a configuration file.

“There are substantial risks including data theft, as Operation DreamJob gathers sensitive system information that could be used for identity theft or espionage. The malware’s ability to delay its actions allows it to evade detection at the moment of penetration and persist longer on the system. By setting specific execution times, it can operate at intervals that might avoid being noticed. Additionally, the malware could manipulate system processes, making it harder to detect and potentially leading to further harm or exploitation of the system,” comments Sojun Ryu, security expert at Kaspersky’s Global Research and Analysis Team.

شارك هذا الموضوع

  • المشاركة على WhatsApp (فتح في نافذة جديدة) WhatsApp
  • المشاركة على Telegram (فتح في نافذة جديدة) Telegram
  • المزيد
  • تدوينة
  • Tweet

مرتبط

RelatedPosts

Money20/20 Middle East Charts Saudi Fintech Future

Cairo Design Week 2026 to Host MENA’s First Cross-Border Design Collective

NetApp Reinforces Commitment to Egypt’s Digital Future Through CONNECT Cairo 2026

Tags: cyberattack

Related Posts

Money20/20 Middle East Charts Saudi Fintech Future
English

Money20/20 Middle East Charts Saudi Fintech Future

سبتمبر 17, 2026
Cairo Design Week
English

Cairo Design Week 2026 to Host MENA’s First Cross-Border Design Collective

يونيو 22, 2026
NetApp
English

NetApp Reinforces Commitment to Egypt’s Digital Future Through CONNECT Cairo 2026

يونيو 21, 2026
English

POPCORN Launches AI Platform for Arabic Video Ad Production

يونيو 11, 2026
Load More

آخر الأخبار

تقرير كاسبرسكي للاستدامة 2024-2025: تعزيز الأمن السيبراني وبناء عالم رقمي أكثر أمانًا للجميع

كاسبرسكي: تراجع التهديدات السيبرانية في مصر 14.5%

سبتمبر 21, 2026
بروتوكول لتمكين المرأة ماليًا

بروتوكول لتمكين المرأة ماليًا

سبتمبر 21, 2026
مصر وNVIDIA تبحثان دعم الذكاء الاصطناعي والابتكار

مصر وNVIDIA تبحثان دعم الذكاء الاصطناعي والابتكار

سبتمبر 21, 2026
انطلاق «إيجيبت ستيتش آند تكس» لدعم صادرات النسيج

انطلاق «إيجيبت ستيتش آند تكس» لدعم صادرات النسيج

سبتمبر 21, 2026
وزير المالية: تطوير الضرائب والجمارك وتعزيز الامتثال

وزير المالية: تطوير الضرائب والجمارك وتعزيز الامتثال

سبتمبر 21, 2026
No Result
View All Result
contact us: info@techno-fin.com Dubai:0553028804 Cairo:01150009990

Follow Us

All rights reserved to www.techno-fin.com, UAE, Sheikh Zayed Road, City Tower 2, 18th floor, office 1801
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English