logo

ClickFake Interview – Lazarus Hackers Exploit Windows and macOS Users Fake Job Campaign

ID: a71f7254-1cfd-55f3-b683-c523a8c0a341

STIX ID: report--a71f7254-1cfd-55f3-b683-c523a8c0a341

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Balaji N

...
...

The report documents Lazarus Group's "ClickFake Interview" campaign that lures cryptocurrency job seekers to fake ReactJS interview sites which prompt downloads that deploy a NodeJS/VBS chain on Windows and Bash/launchd on macOS to install the FrostyFerret stealer and GolangGhost backdoor; the malware provides remote control, credential/browser data theft, and RC4-encrypted C2 communications, and the campaign targets centralized finance platforms following prior large-scale thefts (including a reported $1.5B Bybit heist).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.