logo

Lazarus ClickFake Interview Campaign: ClickFix Malware

ID: 159d434a-9c11-59e3-a8e4-18248d6a6537

STIX ID: report--159d434a-9c11-59e3-a8e4-18248d6a6537

Feed Name: Sekoia.com

Threat Score
90/100

Date Published: 2025-03-31

Date Updated: 2026-07-20

...
...

In March 2025 Sekoia documented the Lazarus-attributed "ClickFake Interview" campaign that lures cryptocurrency job seekers to ReactJS-based fake interview sites, uses a ClickFix social-engineering prompt to make victims run curl commands that fetch platform-specific payloads, and ultimately installs a Go interpreted backdoor (GolangGhost) and a macOS stealer (FrostyFerret); the report provides full infection-chain analysis, IoCs (domains, staging C2s, GolangGhost C2 IPs), file hashes, YARA detections, and hunting/detection guidance and links this activity to prior Contagious Interview operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.