LinkedIn Lures and Lazarus: North Korea’s Latest Job Scam Shenanigans
North Korea’s Lazarus group is back, now using LinkedIn job postings to target software developers. Their bait? Malicious Git repositories that steal source code and cryptocurrency. It’s a reminder that if a job offer seems too good to be true, it probably is—especially if it involves downloading mysterious files!

Hot Take:
North Korea’s Lazarus Group is tapping into the job market’s treasure trove, transforming LinkedIn from a networking haven into a digital den of thieves. If you’re a software developer, beware of recruiters offering dream jobs—your career might just end up being the least of what they steal!
Key Points:
- North Korea’s Lazarus Group is targeting software developers through fake job postings on LinkedIn.
- The campaign, called Operation 99, tricks victims into downloading malicious Git repositories.
- Malware used in the attacks can steal source code, cryptocurrency, and sensitive data.
- Attackers employ sophisticated techniques including AI-generated recruiter profiles.
- Developers are urged to be cautious of too-good-to-be-true job offers, especially those involving file downloads.
Already a member? Log in here