North Korean state advanced persistent threat (APT) group is using Windows Update to spray malware in a campaign powered by a GitHub command-and-control (C2) server. The group once again dangled fake job opportunities at engineers in a spear-phishing campaign that used Windows Update as a living-off-the-land technique and GitHub as a C2. The U.S. refers to Lazarus as Hidden Cobra: a name used to refer to malicious cyber-activity by the North Korean government in general.”]
Source: https://threatpost.com/lazarus-apt-windows-update-malware-github/178096/