logo

North Korean hackers adopt ClickFix attacks to target crypto firms

ID: eb668a5c-de13-5e87-87dd-bcdfbcddfd69

STIX ID: report--eb668a5c-de13-5e87-87dd-bcdfbcddfd69

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-03-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** The North Korean Lazarus group is using ClickFix/ClickFake social‑engineering on fake interview sites to trick CeFi job candidates into executing commands (curl/PowerShell) that install a Go-based backdoor called GolangGhost which establishes persistence, communicates with C2, and harvests browser credentials and system data; Sekoia published technical analysis, Yara rules, and IoCs for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.