North Korean hackers adopt ClickFix attacks to target crypto firms
ID: eb668a5c-de13-5e87-87dd-bcdfbcddfd69
STIX ID: report--eb668a5c-de13-5e87-87dd-bcdfbcddfd69
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** The North Korean Lazarus group is using ClickFix/ClickFake social‑engineering on fake interview sites to trick CeFi job candidates into executing commands (curl/PowerShell) that install a Go-based backdoor called GolangGhost which establishes persistence, communicates with C2, and harvests browser credentials and system data; Sekoia published technical analysis, Yara rules, and IoCs for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
