According to the report, it is alleged that a group of hackers has created PowerShell scripts which enable operators to run different commands on a remote server. Those scripts fall on the server under the facade of WordPress files. When the script is successfully launched, it enables attackers to download and then install app files, go on to update the configuration of the ill server and then gather info about it.
Read the details in the article of Coinidol dot com, the world blockchain news outlet: https://coinidol.com/north-korean-lazarus/
