logo

Beware! Lazarus Hackers Use Fake Interviews “ClickFake” to Infect Windows & macOS with GO Malware

ID: cffd434a-aee9-5751-8ae0-70a4cf45ae99

STIX ID: report--cffd434a-aee9-5751-8ae0-70a4cf45ae99

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-19

Author: Mandvi

...
...

Lazarus has launched the "ClickFake Interview" campaign targeting cryptocurrency job seekers via fake ReactJS interview sites that trick victims into downloading malicious software; Windows victims receive a VBS/NodeJS chain delivering the GolangGhost backdoor, while macOS victims encounter FrostyFerret to harvest credentials before GolangGhost deployment. The report details the malware's encrypted C2, persistence via registry/plist entries, and the campaign's focus on CeFi targets as part of DPRK-linked financially motivated operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.