logo

Lazarus APT Jumps on ClickFix Bandwagon in Recent Attacks

ID: 32fe509b-d63b-5799-9eb2-4026a6653171

STIX ID: report--32fe509b-d63b-5799-9eb2-4026a6653171

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-04-01

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

North Korea-linked Lazarus is running a 'ClickFake Interview' campaign that lures cryptocurrency job seekers via social media to fake interview sites and uses the ClickFix technique to convince victims to paste/run commands that install malware; operators deploy the FrostyFerret infostealer and GolangGhost backdoor on macOS and Windows, targeting CeFi-related employees, and researchers published IoCs and detection/hunting rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.