{"id":133555,"date":"2025-11-18T10:20:11","date_gmt":"2025-11-18T10:20:11","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=133555"},"modified":"2025-11-18T10:23:32","modified_gmt":"2025-11-18T10:23:32","slug":"lazarus-apt-group-new-scoringmathtea-rat","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/","title":{"rendered":"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities"},"content":{"rendered":"\n<p>The Lazarus APT Group has unveiled a new Remote Access Trojan called ScoringMathTea, representing a significant advancement in their cyberattack capabilities.<\/p>\n\n\n\n<p>This C++ based malware was identified as part of Operation DreamJob, a campaign aligned with the North Korean government.<\/p>\n\n\n\n<p>The threat actors have been targeting companies that provide Unmanned Aerial Vehicle technology to Ukraine, aiming to steal critical production knowledge and intellectual property.<\/p>\n\n\n\n<p>ScoringMathTea is distributed through two distinct kill chains and provides operators with comprehensive control over compromised systems.<\/p>\n\n\n\n<p>The malware enables remote command execution, in-memory plugin loading, and various <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> mechanisms that allow attackers to maintain long-term access to infected networks.<\/p>\n\n\n\n<p>What makes this threat particularly dangerous is its sophisticated architecture designed specifically to evade detection across both network and endpoint security systems.<\/p>\n\n\n\n<p>A security analyst and researcher, 0x0d4y, <a href=\"https:\/\/0x0d4y.blog\/arsenal-analysis-of-a-nation-state-actor-an-in-depth-look-at-lazarus-scoringmathtea\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that ScoringMathTea implements multiple layers of obfuscation and evasion techniques.<\/p>\n\n\n\n<p>The malware employs a custom polyalphabetic substitution cipher with chaining to deobfuscate strings at runtime, making static analysis significantly more challenging for security teams.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgsQfDX0EiqaeMCuV3NnYmgq-YpSVQWwTpi1Fc2y74cJjcOM5gzcnAUE1otVp7BwW850pA_BJcukNggiylDO_VI4D4yQjcNiB512uXzzbOXGvqcGjTYjo4fZbNTDtvp50MDl2iWSbPaSVR7GWCZu-5fkS1ZbWJNwALDshW2U6UkuxmAiMzgor7cQQyNIvA\/s16000\/Execution%20chains%20(Source%20-%200x0d4y).webp\" alt=\"Execution chains (Source - 0x0d4y)\" \/><figcaption class=\"wp-element-caption\">Execution chains (Source &#8211; 0x0d4y)<\/figcaption><\/figure><\/div>\n\n\n<p>The decryption mechanism uses a 64-character lookup table and maintains a dynamic key state that changes with each character, effectively preventing simple string <a href=\"https:\/\/cybersecuritynews.com\/free-forensic-investigation-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">extraction tools<\/a> from revealing its configuration details.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-advanced-detection-evasion-through-dynamic-api-resolution\"><strong>Advanced Detection Evasion Through Dynamic API Resolution<\/strong><\/h2>\n\n\n\n<p>The malware&#8217;s most notable defensive feature involves its implementation of API hashing for dynamic resolution. Rather than calling Windows APIs directly, ScoringMathTea resolves APIs at runtime using a custom hashing algorithm.<\/p>\n\n\n\n<p>The algorithm operates with a fixed seed value of 0x2DBB955 and combines character ASCII values with bit-shifted hash operations.<\/p>\n\n\n\n<p>This technique, combined with PEB Walking to locate kernel32.dll independently, enables the malware to bypass traditional API hooking mechanisms employed by security software.<\/p>\n\n\n\n<p>Communication with the command and control server occurs over HTTP or HTTPS using multi-layered encryption. The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> first compresses payloads, then encrypts them using a TEA or XTEA algorithm in CBC mode, and finally applies Base64 encoding.<\/p>\n\n\n\n<p>Additionally, ScoringMathTea spoofs a legitimate Microsoft Edge browser user agent to blend its traffic with normal network activity, making detection through network signatures extremely difficult.<\/p>\n\n\n\n<p>The malware&#8217;s core strength lies in its reflective plugin loading capability, which allows operators to download and execute arbitrary code entirely within memory without ever writing files to disk.<\/p>\n\n\n\n<p>This technique manually implements the Windows Loader and includes an inline CRC32 checksum verification to detect debugger tampering.<\/p>\n\n\n\n<p>Through these sophisticated mechanisms, ScoringMathTea represents a mature threat that demands immediate attention from security teams monitoring advanced persistent threats.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Lazarus APT Group has unveiled a new Remote Access Trojan called ScoringMathTea, representing a significant advancement in their cyberattack capabilities. This C++ based malware was identified as part of Operation DreamJob, a campaign aligned with the North Korean government. The threat actors have been targeting companies that provide Unmanned Aerial Vehicle technology to Ukraine, [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":133616,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-133555","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities<\/title>\n<meta name=\"description\" content=\"ScoringMathTea, a new Lazarus RAT in Operation DreamJob, targets UAV tech firms to steal IP via two kill chains.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities\" \/>\n<meta property=\"og:description\" content=\"ScoringMathTea, a new Lazarus RAT in Operation DreamJob, targets UAV tech firms to steal IP via two kill chains.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-18T10:20:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-18T10:23:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities","description":"ScoringMathTea, a new Lazarus RAT in Operation DreamJob, targets UAV tech firms to steal IP via two kill chains.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/","og_locale":"en_US","og_type":"article","og_title":"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities","og_description":"ScoringMathTea, a new Lazarus RAT in Operation DreamJob, targets UAV tech firms to steal IP via two kill chains.","og_url":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-11-18T10:20:11+00:00","article_modified_time":"2025-11-18T10:23:32+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities","datePublished":"2025-11-18T10:20:11+00:00","dateModified":"2025-11-18T10:23:32+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/"},"wordCount":453,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#primaryimage"},"thumbnailUrl":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/","url":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/","name":"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#primaryimage"},"thumbnailUrl":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-11-18T10:20:11+00:00","dateModified":"2025-11-18T10:23:32+00:00","description":"ScoringMathTea, a new Lazarus RAT in Operation DreamJob, targets UAV tech firms to steal IP via two kill chains.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#primaryimage","url":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/lazarus-apt-group-new-scoringmathtea-rat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"Lazarus APT Group New ScoringMathTea RAT Enables Remote Command Execution Among Other Capabilities"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhglLwSA_RIYCxCcUmG0ZXYUu45wlFiW6zpEo13xCoaKnBGtCv_XOT9ZKqyBP_2KOzTZ7KosJnKcZVcDwF5GPh6zsoAPk1ZTWRY12Y45j9I6SJLadQZBIVIwroHhInURHpD-cioplU05DvVMm4pXFdWvR9RFqvQwpTPpVncrgi_YRvU10-08fAWChQmtKU\/s16000\/Lazarus%20APT%20Group%20New%20ScoringMathTea%20RAT%20Enables%20Remote%20Command%20Execution%20Among%20Other%20Capabilities.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=133555"}],"version-history":[{"count":2,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133555\/revisions"}],"predecessor-version":[{"id":133614,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/133555\/revisions\/133614"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/133616"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=133555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=133555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=133555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}