North Korean threat actors have evolved their attack strategies, now using a social engineering tactic called “ClickFix” to target job seekers in the cryptocurrency industry. This campaign, dubbed “ClickFake Interview” by cybersecurity firm Sekoia, delivers a sophisticated Go-based backdoor called GolangGhost to both Windows and macOS systems.
## Contagious Interview Campaign
The operation, also known as DeceptiveDevelopment or Famous Chollima, has been active since at least December 2022 but was only publicly documented in late 2023. Security researchers attribute this campaign to the notorious Lazarus Group, which operates under North Korea’s Reconnaissance General Bureau (RGB).
Unlike previous campaigns targeting decentralized finance (DeFi) entities, this operation primarily focuses on centralized finance companies by impersonating established firms like Coinbase, KuCoin, Kraken, and Tether.
## Attack Methodology
The attackers approach potential victims through LinkedIn or X (formerly Twitter), inviting them to prepare for video interviews. Victims are directed to a fake video interviewing service called “Willo” and asked to complete a video assessment. When users attempt to enable their camera, they encounter an error message prompting them to download a “driver” to fix the issue—the point where the ClickFix technique is deployed.
Depending on the victim’s operating system:
– Windows users are instructed to execute commands in Command Prompt that ultimately run the GolangGhost backdoor
– macOS users are directed to Terminal commands that deploy both a stealer module (FROSTYFERRET) and the backdoor
The FROSTYFERRET module displays fake prompts requesting camera access and system passwords, which are then exfiltrated to Dropbox, likely to access iCloud Keychain data.
## Expanding IT Worker Scheme
Google’s Threat Intelligence Group reports that North Korea’s fraudulent IT worker scheme has expanded significantly into Europe. These operatives pose as legitimate remote workers to generate illicit revenue for Pyongyang, violating international sanctions.
The IT workers create fabricated personas seeking employment in organizations across Germany, Portugal, and the United Kingdom, often claiming to be from countries like Italy, Japan, Vietnam, and the United States. They’re recruited through platforms including Upwork, Telegram, and Freelancer, with payments processed through cryptocurrency and services like TransferWise and Payoneer to obscure fund origins.
Recent developments show these operatives increasingly targeting companies with Bring Your Own Device policies, where traditional security tools are often absent, and employing extortion tactics when discovered.
Security experts warn that European organizations must recognize this is not just a US problem, as North Korea continues to demonstrate remarkable adaptability in its cyber operations to fund the regime.
