Lazarus Group Uses CookiePlus Malware to Target Nuclear Engineers – Active IOCs

2024-12-23 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-group-uses-cookieplus-malware-to-target-nuclear-engineers-active-iocs

Thumbnail for Lazarus Group Uses CookiePlus Malware to Target Nuclear Engineers – Active IOCs

Lazarus is reported to have targeted at least two employees at an unidentified nuclear-related business in January 2024 through Operation Dream Job, also tracked as NukeSped. The campaign used fake skills tests and trojanized remote-access tools such as VNC or PuTTY, including AmazonVNC.exe and DLL side-loading through vnclang.dll, to deliver MISTPEN, LPEClient, RollMid, CookieTime, and the modular CookiePlus backdoor. CookiePlus masqueraded as software components such as a Notepad++ plugin or DirectX-Wrappers, retrieved Base64-encoded RSA-encrypted payloads from C2, and could run DLLs or shellcode that gathered system data and controlled sleep behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 58f2972c6a8fc743543f7b8c4df085c… 2024-12-19 2026-04-03
HASH f5873ecd60390e7b86db5ddaf158ed2… 2024-12-19 2025-11-20
HASH 6f9b79c20330a7c8ade8285866e5602… 2024-12-19 2024-12-23
HASH ba5f3bbe77eef8e730fde5f7ab493e4… 2024-12-19 2024-12-23
HASH 95dc085b0fea4a8d80df11ba1409a2d… 2024-12-19 2024-12-23

Related Actors

Related Reports

« Back