DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams

ClickFix-style lures have been used by threat actors associated with the Democratic People’s Republic of Korea (often known as North Korea or the DPRK) to spread the well-known malware BeaverTail and InvisibleFerret.

According to a report released last week by Oliver Smith, a researcher with GitLab Threat Intelligence, the threat actor targeted marketing and trader positions in cryptocurrency and retail sector companies using ClickFix lures instead of software development positions.

BeaverTail and InvisibleFerret, which were first made public by Palo Alto Networks in late 2023, have been used by North Korean agents as part of a protracted campaign known as Contagious Interview (also known as Gwisin Gang), in which the malware is given to software developers under the guise of a job evaluation. The cluster has been operational since at least December 2022 and is considered a subset of the umbrella group Lazarus.

BeaverTail has also been spread throughout the years using fake Windows videoconferencing apps like FCCCall and FreeConference read more about DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *