logo

Fake Job Offers – Lazarus Hackers Deploy ClickFix Strategy to Target Windows 11

ID: 399bb548-4279-587a-ac8a-af21b981bfb5

STIX ID: report--399bb548-4279-587a-ac8a-af21b981bfb5

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-08-28

Date Updated: 2026-04-19

Author: Priya

...
...

Lazarus Group’s "ClickFix" campaign lures job-seekers to attacker-controlled interview sites that prompt victims to install a fake Nvidia update (nvidiaRelease.zip). The malicious bundle drops platform-specific loaders (drvUpdate.exe for Windows 11, Node.js main.js, and Python InvisibleFerret; arm64-fixer/drivfixer.sh for macOS) that provide persistence, data exfiltration (BeaverTail infostealer), and C2 communications (e.g., 103.231.75.101:8888, 45.159.248.110). The report includes filenames, IPs, and recommended defenses (use official vendor updates, backups, sandbox analysis).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.