Lazarus has been linked to a new campaign targeting hopeful job candidates in the defense industry. The APT group in its latest operation impersonates Lockheed Martin. The Bethesda, Maryland-based company is involved in aerospace, military technology, mission systems, and space exploration.

See also: Kimsuky: Uses RAT with customized Gold Dragon malware
Lockheed Martin had sales of $65.4 billion in 2020 and has approximately 114,000 employees worldwide.
Lazarus is a state-sponsored hacking group with ties to North Korea. The group is generally financially motivated and is believed to be responsible for serious attacks in the past, starting with the WannaCry ransomware outbreak, as well as the $80 million heist of a Bangladeshi bank, attacks on South Korean shipping companies and supply chains .
On February 8, Qualys Senior Engineer of Threat Research Akshat Pradhan revealed a new campaign that uses the name Lockheed Martin to attack job candidates.
See also: US seizes $3.6 billion stolen from Bitfinex cryptoexchange
In a similar vein to previous activities that abused the reputations of Northrop Grumman and BAE Systems, the Lazarus Group sends targets phishing documents pretending to offer employment opportunities.
The documents, named Lockheed_Martin_JobOpportunities.docx and Salary_Lockheed_Martin_job_opportunities_confidential.doc, contain malicious macros that trigger shellcode to hijack control flow, retrieve decoy documents, and create Scheduled tasks for persistence.

Living Off the Land Binaries (LOLBins) are also abused to further compromise the target machine. However, when the malicious scripts attempted to pull in an additional payload, an error was returned — so Qualys cannot be sure what the final malware package was intended to accomplish.
This is not the first time that Lazarus has exploited job candidates. F-Secure has previously identified samples of phishing emails disguised as job offers sent to a system administrator belonging to a targeted cryptocurrency organization.
See also: Google: Fixes critical vulnerabilities in Android devices
In a related study, Outpost24's Blueliv cybersecurity team has named Lazarus, Cobalt, and FIN7 as the most prevalent groups targeting the financial industry.
Information source: zdnet.com
