{"repo":"ZeroMemoryEx/APT38-0day-Stealer","free":true,"listed":false,"github":"https://github.com/ZeroMemoryEx/APT38-0day-Stealer","clone":"git clone https://github.com/ZeroMemoryEx/APT38-0day-Stealer.git","description":"APT38 Tactic PoC for Stealing 0days from security researchers","language":"C++","stars":333,"topics":["win32api","rce","malware","visual-studio","lazarus","malware-research","red-team","0day","0day-stealer","apt-38"],"license":null,"category":"workflow-automation","readme_excerpt":"Lazarus-Tactic A program that automates the APT38 technique, which has been utilized to target cybersecurity researchers experts Lazarus is a state-sponsored group affiliated with North Korea, has a well-documented track record of targeting cybersecurity researchers. Among their notable techniques, one stands out for its effectiveness in tricking numerous cybersecurity experts. The attackers create multiple Twitter and other social media accounts to establish credibility. Through social engineering tactics, they manipulate security researchers into engaging in collaborative research using a Microsoft Visual Studio Project, the project contains a malicious code in the vcxproj file. Consequently, when the researcher attempts to build the project, the malicious code embedded within it is executed. Attack Scenario: Developer Environment Supply Chain Attack An attacker sends a malicious Visual Studio project to a developer, the developer opens the project, appearing to be a legitimate code sample, Upon first build, the program infects ALL Visual Studio projects on the developer's system The infected developer continues normal work, modifying and sharing projects with colleagues and each shared project carries the infection to new developer machines and when colleagues open and build these projects, their environments become infected the infection continues to spread across the development team Impact In a successful campaign, this will create a catastrophic compromise of the entir","default_branch":null,"files":null,"tree":[],"storefront":"/r/ZeroMemoryEx","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/ZeroMemoryEx/APT38-0day-Stealer/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}