موقع إلكتروني متخصص في الأخبار الاقتصادية
الأربعاء, 30 سبتمبر 2026 | 8:19 مساءً
آخر الأخبار
«أورا العراق» تسند أعمال إنشاءات المرحلة الأولى بمشروع «مدينة الورد» لشركة «درة» شركة «Ai BEYOT» تقدم نموذجاً جديداً للحلول المعيارية والمباني سابقة التجهيز في السوق المصري مدينة دهب تتصدر مؤشر «IQOS» لأفضل وجهات المطاعم والجلسات الخارجية في الشرق الأوسط «سي آي كابيتال لإدارة الأصول» تفعل تفويض إدارة استثمارات صندوق السلام التابع للاتحاد الأفريقي تحالف «إنوفو – ريدكون» يقتنص أعمال مشروع «وادي يم» برأس الحكمة بقيمة 12 مليار جنيه بنك نكست يوقع عقد تسهيلات ائتمانية بـ 2.1 مليار جنيه مع مجموعة عز العرب السويدي «مدينة مصر» تسند أعمالاً إنشائية بمشروع «أوريجامي» في تاج سيتي بقيمة 1.38 مليار جنيه «أسترازينيكا» تتعاون مع «اليونيسف» لتدريب 5000 شاب وتجهيز المدارس لمواجهة التحديات الصحية «هواوي» تستعرض حلول الطاقة الرقمية لدعم عمليات قطاع التعدين في مصر خلال منتدى التعدين 2026 مؤسسة ساويرس وJ-PAL MENA تطلقان ملتقى «الأثر القائم على الأدلة» لتوجيه الاستثمارات المجتمعية
اعلان كبير اسفل السلايدر

Kaspersky Exposes Lazarus’ New Campaign Exploiting Legitimate Software

اعلان كبير اسفل قسم الاخبار

A new campaign by the infamous Lazarus group targeting organizations worldwide has been uncovered by Kaspersky’s Research and Analysis Team (GReAT).

The research presented at Security Analyst Summit (SAS) revealed a sophisticated APT campaign distributed via malware and spread through legitimate software.

The GReAT team identified a series of cyber incidents that involved targets being infected through legitimate software designed to encrypt web communication using digital certificates. Despite vulnerabilities being reported and patched, organizations worldwide still used the flawed version of the software, providing an entry point for the infamous Lazarus group.

اعلانات بجانب السلايدر 2

The adversary exhibited a high level of sophistication, employing advanced evasion techniques and deploying a “SIGNBT” malware to control the victim. They also applied the already well-known LPEClient tool, previously seen targeting defense contractors, nuclear engineers and the cryptocurrency sector. This malware acts as the initial point of infection and plays a crucial role in profiling the victim and delivering the payload. Kaspersky researchers’ observations indicate that LPEClient’s role in this and other attacks aligns with the tactics employed by the Lazarus group, as also seen in the notorious 3CX supply chain attack.

Further investigation revealed that the Lazarus malware had already targeted the initial victim, a software vendor, several times before. This pattern of recurring attacks indicates a determined and focused adversary, likely with an intention is to steal critical source code or disrupt the software supply chain. The threat actor consistently exploited vulnerabilities in the company’s software and broadened their scope by targeting other companies that used the unpatched version of the software. Kaspersky’s Endpoint Security solution identified the threat proactively and prevented further attacks against other targets.

“The Lazarus group’s continued activity is a testament to their advanced capabilities and unwavering motivation. They operate on a global scale, targeting a wide range of industries with a diverse toolkit of methods. This signifies an ongoing and evolving threat that demands heightened vigilance,” said Seongsu Park, Lead Security Researcher at Kaspersky’s Global Research and Analysis Team.

اترك ردًا

لن يتم نشر عنوان بريدك الإلكتروني.