HomeSecurityLazarus team exploits Git symlink vulnerability

Lazarus team exploits Git symlink vulnerability

Earlier this month, cybersecurity researchers uncovered a new phishing campaign attributed to the Lazarus Group, which targets developers and cryptocurrency professionals through a cleverly designed Git symlink vulnerability

See also: Lazarus APT uses ClickFix technique to steal data

Lazarus Git

Rather than relying solely on traditional malware distribution channels, attackers have weaponized the way Git handles repository paths, embedding malicious hooks inside symbolic links to trigger code execution during routine operations. This technique allows attackers to maintain a low profile while compromising high-value targets who assume their development workflows are immune to social engineering.

The initial approach begins with personalized messages on professional networking platforms, where potential victims are invited to participate in a mock technical interview. The conversation is structured to gain the victim’s trust and convince them to execute a Git clone. Additionally, the repository contains an embedded directory named api/db_drivers, which is actually a symbolic link pointing back to the .git . This deceptive structure ensures that once Git performs a checkout operation, it unwittingly executes the attacker’s custom hook script.

KuCoin analysts first noted this attack pattern in late August, following reports of compromised private GitLab repositories. Detailed analysis revealed that the symlink exploit leverages Git’s post-checkout hook mechanism to launch a hidden backdoor. By embedding a malicious post-checkout script within the symbolic link, attackers achieve code execution without modifying the main code base, thus bypassing standard integrity checks and static scanners.

See also: Lazarus hackers deploy three RATs on compromised systems

Lazarus team exploits Git symlink vulnerability

Subsequent forensic examination confirmed that the payload establishes an encrypted connection to a remote command and control server, siphoning credentials, system information, and wallet data back to the attackers. The sophistication of the exploit lies in its seamless integration with legitimate workflows. Victims report that after the malicious hook is executed, it is automatically activated. The embedded script, hooks/post-checkout, calls a Node.js backdoor. Once deployed, this backdoor maintains its persistence by cleaning and replacing project files to remove obvious signs of tampering, ensuring that developers only see the expected code.

The infection proceeds in two coordinated phases: exploiting Git's path resolution and silently executing the hook. First, the attackers create a repository with a directory entry named api/db_drivers, exploiting the transfer backhandler to write the path as api/db_drivers to disk while keeping the symlink target internally. This mismatch confuses Git into treating the path as a regular directory during traversal, but as a link when initializing the hooks. As Git performs its default checkout operation, it follows the hidden symbolic link to the .git/modules/api/db_drivers/hooks/ and executes the post-checkout script.

See also: BitoPro links Lazarus to $11 million crypto theft

North Korean defense industry hackers

By exploiting a fundamental behavior of Git, the Lazarus team has demonstrated a new level of technical ingenuity, combining supply chain breaching with social engineering to target high-value individuals. The campaign serves as a stark reminder that even the most trusted development tools can be weaponized when assumptions about the integrity of the workflow are not challenged.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS