Fake Job Offers – Lazarus Hackers Deploy ClickFix Strategy to Target Windows 11
ID: 399bb548-4279-587a-ac8a-af21b981bfb5
STIX ID: report--399bb548-4279-587a-ac8a-af21b981bfb5
Feed Name: Cyber Press
Lazarus Group’s "ClickFix" campaign lures job-seekers to attacker-controlled interview sites that prompt victims to install a fake Nvidia update (nvidiaRelease.zip). The malicious bundle drops platform-specific loaders (drvUpdate.exe for Windows 11, Node.js main.js, and Python InvisibleFerret; arm64-fixer/drivfixer.sh for macOS) that provide persistence, data exfiltration (BeaverTail infostealer), and C2 communications (e.g., 103.231.75.101:8888, 45.159.248.110). The report includes filenames, IPs, and recommended defenses (use official vendor updates, backups, sandbox analysis).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
