CyberSecurity news
do son@securityonline.info
//
A new "ClickFake Interview" campaign, attributed to the Lazarus Group, is targeting professionals in the cryptocurrency sector with fraudulent job offers. Security researchers at Sekoia discovered the operation, revealing that threat actors impersonate recruiters on platforms like LinkedIn and X (formerly Twitter) to lure victims into fake job interviews. These interviews are designed to trick candidates into opening malicious documents or clicking on compromised links, ultimately leading to malware infection and potential data theft.
The malware, dubbed "ClickFix" or sometimes distributed through the GolangGhost backdoor, grants attackers remote access to compromised systems. This allows the Lazarus Group to steal sensitive information, including cryptocurrency wallet credentials, execute arbitrary commands, and maintain persistent access. Sekoia warns that this campaign reflects a new Lazarus strategy targeting cryptocurrency industry employees, even those with limited technical expertise, making them less likely to detect malicious activity during the interview process. Professionals are advised to verify recruiter identities, avoid downloading files from unknown sources, and utilize endpoint protection to mitigate risks.
ImgSrc: securityonline.
References :
- : New “ClickFake Interview” campaign attributed to the Lazarus Group targets crypto professionals with fake job offers
- www.scworld.com: ClickFix technique leveraged in new crypto-targeted Lazarus attacks
- Virus Bulletin: Sekoya researchers discovered a ClickFake Interview campaign targeting job seekers with fake job interview websites. The infrastructure aligns with technical indicators linked to the Contagious Interview campaign and delivers GolangGhost backdoor for Windows & macOS
- Security Risk Advisors: Lazarus Uses “ClickFake Interview� to Distribute Backdoors via Fake Crypto Job Websites
- The Hacker News: Lazarus Group Targets Job Seekers With ClickFix Tactic to Deploy GolangGhost Malware
Classification:
- HashTags: #ClickFake #Lazarus #Backdoor
- Company: Secoia
- Target: job seekers
- Attacker: Lazarus
- Product: interview
- Feature: fake interviews
- Malware: GolangGhost
- Type: Espionage
- Severity: Major