Lazarus ClickFake Interview Campaign: ClickFix Malware
ID: 159d434a-9c11-59e3-a8e4-18248d6a6537
STIX ID: report--159d434a-9c11-59e3-a8e4-18248d6a6537
Feed Name: Sekoia.com
In March 2025 Sekoia documented the Lazarus-attributed "ClickFake Interview" campaign that lures cryptocurrency job seekers to ReactJS-based fake interview sites, uses a ClickFix social-engineering prompt to make victims run curl commands that fetch platform-specific payloads, and ultimately installs a Go interpreted backdoor (GolangGhost) and a macOS stealer (FrostyFerret); the report provides full infection-chain analysis, IoCs (domains, staging C2s, GolangGhost C2 IPs), file hashes, YARA detections, and hunting/detection guidance and links this activity to prior Contagious Interview operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
