From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic
ID: caf3ab74-0f21-5b04-b5db-f35a67c6faa8
STIX ID: report--caf3ab74-0f21-5b04-b5db-f35a67c6faa8
Feed Name: Sekoia.io Blog
Date Published: 2025-03-31
Date Updated: 2026-04-29
Author: Amaury G., Coline Chavane, Felix Aimé and Sekoia TDR
Sekoia documents a Lazarus-run campaign called "ClickFake Interview" that lures cryptocurrency job seekers to ReactJS-based fake interview sites, uses a ClickFix prompt to persuade victims to run OS-specific commands, and ultimately installs a Go-based interpreted backdoor (GolangGhost) on Windows/macOS and a macOS stealer (FrostyFerret) to exfiltrate credentials and browser data; the report includes IoCs (domains, C2 IPs, file hashes), YARA rules, and detection/hunting guidance and links the activity to the broader Contagious Interview operations targeting CeFi firms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
