The notorious North Korean hacking group Lazarus has reportedly adopted 'ClickFix' tactics to develop malware targeting cryptocurrency job seekers, particularly at CeFi.
See also: New ClickFix attack deploys Havoc C2 via Sharepoint

This development, as Sekoia reports, is considered an evolution of the specific malicious actor's 'Contagious Interview' campaign, which also targets job seekers in the fields of artificial intelligence and cryptocurrency.
The ClickFix tactic is a relatively new but increasingly prevalent one, where threat actors use fake errors on web pages or documents that indicate a problem with displaying content. The page then prompts the user to “fix” the issue by running PowerShell that download and execute malware on the system.
Sekoia reports that the Lazarus group is impersonating many well-known companies in its recent campaign, including Coinbase, KuCoin, Kraken, Circle, Securitize, BlockFi, Tether, Robinhood , and Bybit, from which North Korean hackers recently stole a record $1.5 billion.
In the Contagious campaign, first documented in November 2023, Lazarus approached candidates via LinkedIn or X, offering them job opportunities. It then used software and coding test projects hosted on collaboration platforms like GitHub and Bitbucket to trick targets into downloading and executing malicious loaders on their systems, installing information stealers.
Since February 2025, Sekoia reports that Lazarus has begun using so-called 'ClickFake' campaigns, which implement ClickFix tactics to achieve the self-infection step, while keeping the previous phases of the attack unchanged. However, the researchers note that Contagious Interview is still in progress, suggesting that hackers are likely evaluating the effectiveness of the two techniques while executing them in parallel.
See also: Hackers exploit ClickFix to deploy NetSupport RAT
In the ClickFake attacks, the Lazarus team changed strategy, shifting its focus from developers to people in non-technical roles at CeFi companies, such as business developers and marketing managers.

These individuals are invited to a remote interview via a link that leads to a seemingly legitimate website built in ReactJS, which includes contact forms, open-ended questions, and a request for a video presentation.
When the target tries to record video using computer , a fake error appears claiming that there is a problem with the driver, blocking access to the camera, and providing instructions on how to fix the problem.
Based on the browser's User-Agent , the website provides operating system -specific instructions , supporting either Windows or macOS. Victims are instructed to run a curl command in CMD (Windows) or Terminal (macOS), which infects them with a Go-based backdoor called ' GolangGhost ' and ensures its continued presence by modifying the registry and LaunchAgent plist files .
Once deployed, GolangGhost connects to the command and control (C2) server, registers the newly infected device with a unique machine ID, and waits for commands. The malware has the ability to perform file operations, execute shell commands, steal cookies , browsing history, and saved passwords, as well as collect system metadata.
See also: Alarming rise in ClickFix attacks via Malvertising “DeceptionAds”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Lazarus hacking group, now using the ClickFix technique, is one of the most well-known and dangerous cyberattack groups in the world. It is suspected that the group is linked to the North Korean government, although the country has never admitted its involvement. The Lazarus group has carried out numerous attacks on government systems, banking institutions, large companies and organizations worldwide, with the aim of stealing money, obtaining information and causing general destabilization. The group uses various techniques, such as phishing, malware (malicious software), and exploiting system vulnerabilities to carry out its attacks. It is also known to use highly sophisticated tools to cover its tracks and maintain its anonymity.
Source: bleepingcomputer
