North Korean threat actors are evolving their cyber attack strategies, moving beyond their traditional focus on software developers to target marketing professionals and cryptocurrency traders, according to new research from GitLab Threat Intelligence.
## ClickFix Tactics Target New Sectors
The Democratic People’s Republic of Korea (DPRK)-linked hackers are now using ClickFix social engineering techniques to distribute BeaverTail and InvisibleFerret malware. Unlike previous campaigns that primarily targeted software developers, these attacks focus on marketing and trading roles within cryptocurrency and retail organizations.
“The threat actor’s targeting of marketing applicants and impersonation of a retail sector organization is noteworthy given BeaverTail distributors’ usual focus on software developers,” said GitLab researcher Oliver Smith.
## The Contagious Interview Campaign Evolution
The malware distribution is part of the ongoing “Contagious Interview” campaign, operated by the Lazarus-affiliated Gwisin Gang since December 2022. The group creates fake hiring platforms using services like Vercel, advertising positions at Web3 companies and urging targets to invest in cryptocurrency ventures.
The attack process involves:
– Victims visiting fake job sites that capture their IP addresses
– Instructions to complete video assessments
– Fake technical errors requiring users to run malicious commands
– Deployment of streamlined BeaverTail malware variants
## Technical Improvements and Adaptations
Recent BeaverTail variants show significant modifications:
– **Simplified targeting**: Only eight browser extensions compared to 22 in previous versions
– **Limited browser support**: Focuses solely on Google Chrome data theft
– **Cross-platform deployment**: Compiled binaries for Windows, macOS, and Linux
– **Enhanced evasion**: Password-protected archives for payload delivery
A joint investigation by SentinelOne, SentinelLabs, and Validin revealed that at least 230 individuals were targeted between January and March 2025, with attackers impersonating legitimate companies like Robinhood and eToro.
## Intelligence Gathering Operations
North Korean hackers are actively monitoring cybersecurity intelligence to improve their operations. They examine threat intelligence reports, evaluate new infrastructure, and monitor detection systems through platforms like VirusTotal and Maltrail.
“Their operational strategy appears to prioritize promptly replacing infrastructure lost due to takedown efforts,” researchers noted, indicating a focus on sustainability over security improvements.
## New Threats from APT37 and Kimsuky
**ScarCruft (APT37)** has introduced new tools:
– **CHILLYCHINO**: A Rust-based implant marking APT37’s first use of Rust malware
– **FadeStealer**: A surveillance tool capable of keylogging, screenshots, and data exfiltration
– **VCD ransomware**: Representing a shift toward financially motivated attacks
**Kimsuky (APT43)** has launched two notable campaigns:
1. **GitHub abuse**: Using repositories to host malicious PowerShell scripts with embedded private tokens
2. **Deepfake military IDs**: Leveraging ChatGPT to create fake South Korean military identification cards for spear-phishing attacks against defense personnel and North Korea researchers
## Key Takeaways
These developments highlight North Korean cyber groups’ continuous adaptation and expansion of targets beyond traditional tech sectors. Organizations in cryptocurrency, retail, and defense industries should implement enhanced security measures, including:
– Monitoring suspicious GitHub API traffic
– Training employees on ClickFix social engineering tactics
– Implementing robust email security for spear-phishing protection
– Regular security awareness training for non-technical staff
The evolution from purely espionage-focused operations to financially motivated attacks demonstrates the growing sophistication and diversification of North Korean cyber capabilities.
