DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams
ClickFix-style lures have been used by threat actors associated with the Democratic People's Republic of Korea (often known as North Korea or the DPRK) to spread the well-known malware BeaverTail and InvisibleFerret.
According to a report released last week by Oliver Smith, a researcher with GitLab Threat Intelligence, the threat actor targeted marketing and trader positions in cryptocurrency and retail sector companies using ClickFix lures instead of software development positions.
BeaverTail and InvisibleFerret, which were first made public by Palo Alto Networks in late 2023, have been used by North Korean agents as part of a protracted campaign known as Contagious Interview (also known as Gwisin Gang), in which the malware is given to software developers under the guise of a job ...

