GreenEconomy.MediaSouth Africa's green economy intelligence hub
AnalysisIntelligenceEnvironment

Kaspersky discovers Lazarus APT targets nuclear organisations with new CookiePlus malware

By steven · 17 January 2025 · 2 min read · 0 views

Kaspersky discovers Lazarus APT targets nuclear organisations with new CookiePlus malware

Lazarus’ key operation – “Operation DreamJob” – continues to evolve with new sophisticated tactics that have persisted for more than five years, according to Kaspersky’s Global Research and Analysis Team (GReAT). The latest targets include employees from a nuclear-related organisation, who were infected via three compromised archive files appearing to be skill assessment tests for IT professionals. This ongoing campaign leverages a range of advanced malware, including a newly discovered modular backdoor, CookiePlus, that was disguised as open-source plugin.

Kaspersky’s GReAT discovered a new campaign linked to the infamous Operation DreamJob, also known as DeathNote, a cluster associated with the notorious Lazarus group. Over the years, this campaign has evolved significantly, initially emerging in 2019, with attacks targeting worldwide cryptocurrency-related businesses. During 2024, it expanded to target IT and defense companies across Europe, Latin America, South Korea, and Africa. Kaspersky’s latest report provides new insights into a recent phase of their activity, revealing a campaign targeting employees working at the same nuclear-related organisation in Brazil as well as employees of an unidentified sector in Vietnam.

Over the span of one month, at least two employees from the same organisation were targeted by Lazarus, receiving multiple archive files disguised as skill assessments for IT positions at prominent aerospace and defense companies. Lazarus initially delivered the first archive to Hosts A and B within the same organisation, and after a month, attempted more aggressive attacks on the first target. They likely used job search platforms like LinkedIn to deliver the initial instructions and gain access to the targets.

Lazarus has evolved its delivery methods and improved persistence through a complex infection chain involving various types of malware, such as a downloader, loader, and backdoor. They launched a multi-stage attack using trojanised VNC software, a remote desktop viewer for Windows, and another legitimate VNC tool to deliver malware. The first stage involved a trojanised AmazonVNC.exe, which decrypted and executed a downloader called Ranid Downloader to extract internal resources of the VNC executable. A second archive contained a malicious vnclang.dll that loaded MISTPEN malware, which then fetched additional payloads, including RollMid and a new variant of LPEClient.

Route of malicious files created on victims host

Additionally, they deployed an unseen plugin-based backdoor which GReAT experts dubbed CookiePlus. It was disguised as ComparePlus, an open-source Notepad++ plugin. Once established, the malware collects system data, including the computer name, process ID, and file paths, and makes its main module “sleep” for a set amount of time. It also adjusts its execution schedule by modifying a configuration file.

“There are substantial risks including data theft, as Operation DreamJob gathers sensitive system information that could be used for identity theft or espionage. The malware’s ability to delay its actions allows it to evade detection at the moment of penetration and persist longer on the system. By setting specific execution times, it can operate at intervals that might avoid being noticed. Additionally, the malware could manipulate system processes, making it harder to detect and potentially leading to further harm or exploitation of the system,” comments Sojun Ryu, security expert at Kaspersky’s Global Research and Analysis Team.

Learn more about new Lazarus campaign at Securelist.com.

TagsCookiePlus malwareKasperskyLazarus APTnuclear organisationsOperation DreamJobBusiness & investmentTechnology
Share

steven

Writing for GreenEconomy.Media

URL preservedThis post keeps its original address /kaspersky-discovers-lazarus-apt-targets-nuclear-organisations-with-new-cookieplus-malware/, nothing is re-slugged, so no search ranking is lost in the migration.

Show SEO & AI-citation metadata for this article

DemoEvery article carries this structured metadata so it surfaces in search and can be cited by AI answer engines. In the back end, a person posting fills these in, or the AI layer drafts them.

Meta titleKaspersky discovers Lazarus APT targets nuclear organisations with new CookiePlus malware | GreenEconomy.Media
Meta descriptionLazarus’ key operation – “Operation DreamJob” – continues to evolve with new sophisticated tactics that have persisted for more than five years, according
Meta keywordsNot set
URL slug/article/kaspersky-discovers-lazarus-apt-targets-nuclear-organisations-with-new-cookieplus-malware
Schema.org typeNewsArticle (JSON-LD embedded)

More from Environment

AnalysisEnvironment

Allianz Risk Barometer 2025: Cyber top business risk as climate change hits record high

Cyber incidents such as data breaches or ransomware attacks, and IT disruptions, such as the CrowdStrike incident, are the biggest worry for companies globally in 2025, according to the Allianz Risk Barometer. Once again, Business interruption is also a main concern for companies of all sizes, ranking #2. After another heavy year of natural catastrophes

17 Jan 2025 · steven · 8 min read