North Korean Lazarus Group Deploys “ClickFix” Malware Scam Targeting Crypto Job Seekers

# North Korean Lazarus Group Adopts “ClickFix” Tactics to Target Cryptocurrency Industry

The notorious North Korean Lazarus hacking group has evolved its attack strategy by implementing “ClickFix” tactics to deploy malware against job seekers in the cryptocurrency industry, particularly those in centralized finance (CeFi) roles.

## New Attack Strategy: ClickFake Campaign

Security firm Sekoia reports that Lazarus has expanded beyond its “Contagious Interview” campaign with a new approach called “ClickFake.” This tactic presents users with fake error messages on websites or documents, prompting them to “fix” the issue by running PowerShell commands that actually download and execute malware.

The group impersonates prominent cryptocurrency companies including Coinbase, KuCoin, Kraken, Circle, Securitize, BlockFi, Tether, Robinhood, and Bybit—the latter from which Lazarus recently stole $1.5 billion.

## Shifting Target Profile

While the Contagious Interview campaign primarily targeted developers and coders, ClickFake focuses on non-technical roles such as business developers and marketing managers at CeFi companies. The attack begins with LinkedIn or X messages offering employment opportunities, directing victims to legitimate-appearing ReactJS sites with contact forms and interview questions.

## Infection Method

When victims attempt to record a video introduction, a fake error appears claiming camera access is blocked due to driver issues. The site provides OS-specific instructions for Windows or macOS, prompting victims to run curl commands that install a Go-based backdoor called “GolangGhost.”

Once deployed, this malware:
– Connects to command and control servers
– Registers the infected device with a unique ID
– Performs file operations and executes shell commands
– Steals Chrome cookies, browsing history, and stored passwords
– Harvests system metadata

## Protection Measures

To protect against these attacks, users should:
– Verify interview invitations thoroughly
– Never execute commands copied from the internet without understanding them
– Use Sekoia’s published Yara rules to detect ClickFake activity

Sekoia notes that Lazarus continues to run both Contagious Interview and ClickFake campaigns simultaneously, likely evaluating their comparative effectiveness.

Share This Article