• About Us
  • Privacy Policy
  • Contact Us
Subscribe
BitcoinCryptos - News About Bitcoin & Cryptos
  • Home
  • Bitcoin
  • Ethereum
  • Dogecoin
  • Litecoin
  • Cryptocurrency
  • Blockchain
  • Regulation
  • Market
  • Prices
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Dogecoin
  • Litecoin
  • Cryptocurrency
  • Blockchain
  • Regulation
  • Market
  • Prices
No Result
View All Result
BitcoinCryptos
No Result
View All Result
Home Regulation

Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware

April 5, 2025
in Regulation
0
Lazarus Group Evolves Tactics to Target CeFi Job Seekers with ‘ClickFix’ Malware
Share on FacebookShare on Twitter



A recent cybersecurity report by Sekoia revealed an evolving threat posed by the Lazarus Group, the notorious North Korea-linked hacking group. It is now leveraging a tactic known as “ClickFix” to target job seekers in the cryptocurrency sector, particularly within centralized finance (CeFi).

This approach marks an adaptation of the group’s earlier “Contagious Interview” campaign, which was previously aimed at developers and engineers in artificial intelligence and crypto-related roles.

Lazarus Exploits Crypto Hiring

In the newly observed campaign, Lazarus has shifted its focus to non-technical professionals, such as marketing and business development personnel, by impersonating major crypto firms like Coinbase, KuCoin, Kraken, and even stablecoin issuer Tether.

The attackers build fraudulent websites mimicking job application portals and lure candidates with fake interview invitations. These sites often include realistic application forms and even requests for video introductions, fostering a sense of legitimacy.

However, when a user attempts to record a video, they are shown a fabricated error message, which typically suggests a webcam or driver malfunction. The page then prompts the user to run PowerShell commands under the guise of troubleshooting, thereby triggering the malware download.

This ClickFix method, though relatively new, is becoming more prevalent due to its psychological simplicity – since users believe they are resolving a technical issue, and not executing malicious code. According to Sekoia, the campaign draws on materials from 184 fake interview invitations, referencing at least 14 prominent companies to bolster credibility.

As such, the latest tactic demonstrates Lazarus’s growing sophistication in social engineering and its ability to exploit the professional aspirations of individuals in the competitive crypto job market. Interestingly, this shift also suggests that the group is expanding its targeting criteria by aiming not just at those with access to code or infrastructure but also at those who might handle sensitive internal data or be in a position to facilitate breaches inadvertently.

Despite the emergence of ClickFix, Sekoia reported that the original Contagious Interview campaign remains active. This parallel deployment of strategies suggests that North Korea’s state-sponsored collective may be testing their relative effectiveness or tailoring tactics to different target demographics. In both cases, the campaigns share a consistent goal – delivering info-stealing malware through trusted channels and manipulating victims into self-infection.

Lazarus Behind Bybit Hack

The Federal Bureau of Investigation (FBI) officially attributed the $1.5 billion attack on Bybit to the Lazarus Group. Hackers targeting the crypto exchange employed fake job offers to trick staff into installing tainted trading software known as “TraderTraitor.”

Although crafted to look authentic through cross-platform JavaScript and Node.js development, the applications embedded malware designed to steal private keys and execute illicit transactions on the blockchain.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Related articles

From $108K to $92K (Market Update)

Bitcoin Hits $115K After CPI Data and Ahead of FOMC as BNB, HYPE Break Records: Your Weekly Recap

September 12, 2025
21Shares Files for SEC Approval to Launch Spot Dogecoin ETF

500 Million DOGE Bought, 1 Billion Target in Sight

September 12, 2025



Source link

Tags: CeFiClickFixevolvesGroupJobLazarusMalwareSeekerstacticsTarget
Share76Tweet47

Related Posts

From $108K to $92K (Market Update)

Bitcoin Hits $115K After CPI Data and Ahead of FOMC as BNB, HYPE Break Records: Your Weekly Recap

September 12, 2025
0

The business week was marked by important macroeconomic events, including the much-anticipated CPI data for August, which could set the...

21Shares Files for SEC Approval to Launch Spot Dogecoin ETF

500 Million DOGE Bought, 1 Billion Target in Sight

September 12, 2025
0

CleanCore Solutions has reached the halfway mark in its plan to acquire up to 1 billion Dogecoin within 30 days,...

What Fuels the Massive Rally?

What Fuels the Massive Rally?

September 12, 2025
0

TL;DR M’s triple-digit surge in the last 30 days could be attributed to MemeCore’s latest partnerships and other factors. While...

Judge Pauses SEC Lawsuit Against Coinbase

Coinbase Demands Sanctions Over Destroyed SEC Communications

September 12, 2025
0

Coinbase has filed a motion demanding court sanctions against the U.S. Securities and Exchange Commission (SEC) after discovering that nearly...

‘Legendary Gains or Legendary Regrets:’ Crucial Guidance to Investors After Bitcoin’s New ATH

Bitcoin Eyes $120K if Weekly Close Holds Above $114K

September 12, 2025
0

TL;DR Bitcoin rebounds from $107K low, testing $114K as bulls eye a breakout toward $120K. Liquidations near $115K fueled sharp...

Load More
Bitcoin Miners Accumulate Again: Are New Highs Coming?

Bitcoin Miners Accumulate Again: Are New Highs Coming?

September 13, 2025
0

Key takeaways:Strong Bitcoin miner and corporate BTC accumulation fuel speculation on BTC price surpassing $140,000.Investors’ rising inflation expectations and weakening...

Kashi Is Ready To Fight For Prediction Markets Amid New Lawsuit

Kashi Is Ready To Fight For Prediction Markets Amid New Lawsuit

September 13, 2025
0

Prediction market platform Kalshi has vowed to fight a new lawsuit from the US state of Massachusetts, which accuses the...

Kashi Is Ready To Fight For Prediction Markets Amid New Lawsuit

Kashi Is Ready To Fight For Prediction Markets Amid New Lawsuit

September 13, 2025
0

Prediction market platform Kalshi has vowed to fight a new lawsuit from the US state of Massachusetts, which accuses the...

Gemini Shares Surge 40% Following $28 Nasdaq IPO Amid Crypto Market Rally

Gemini Shares Surge 40% Following $28 Nasdaq IPO Amid Crypto Market Rally

September 13, 2025
0

Key NotesThe cryptocurrency exchange raised $425 million with demand exceeding available shares by over 20 times during its IPO.Winklevoss twins...

Winklevoss brothers tell CNBC Bitcoin could rise 10x and urge viewers to HODL

Winklevoss brothers tell CNBC Bitcoin could rise 10x and urge viewers to HODL

September 13, 2025
0

Key Takeaways The Winklevoss brothers appeared on CNBC to discuss Bitcoin investment strategy. They advised viewers to 'HODL,' or hold...

We have all the news related to the crypto market and we make sure to bring and publish all the updates as fast as we can.

Categories

  • Bitcoin
  • Blockchain
  • Cryptocurrency
  • Dogecoin
  • Ethereum
  • Litecoin
  • Market
  • Regulation

Archives

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021

Newsletter

    • About Us
    • Privacy Policy
    • Contact Us

    © 2021 bitcoincryptos.com

    Please enter CoinGecko Free Api Key to get this plugin works.
    No Result
    View All Result
    • Home
    • Bitcoin
    • Ethereum
    • Dogecoin
    • Litecoin
    • Cryptocurrency
    • Blockchain
    • Regulation
    • Market
    • Prices

    © 2018 JNews by Jegtheme.