Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Social Engineering - New Lazarus Group Scam Targets Crypto Jobseekers
Social Engineering Attacks Latest News News & Analysis

New Lazarus Group Scam Targets Crypto Jobseekers

Adam ParlettBy Adam ParlettApril 2, 2025Updated:April 2, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Lazarus
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The infamous Lazarus cyber threat group, famed for their record-breaking $1.5 billion ByBit crypto heist, has unleashed another attack against the crypto community. In their latest criminal campaign, dubbed ClickFake Interview, the gang is using fake job interviews to target cryptocurrency professionals. 

Please, Take a Seat 

The ClickFake Interview operation can be understood as the latest iteration of similar campaigns, such as the DeceptiveDevelopment and Contagious Interview attacks, also undertaken by Lazarus, involving phony job interviews for fictitious positions. In both attacks, candidates were duped into downloading and running BeaverTail downloader malware that delivers InvisibleFerret, a cross-platform Python backdoor equipped with remote control, keylogging, and browser-stealing capabilities. 

In these latest ClickFake Interview attacks, Lazarus has evolved its social engineering tactics by implementing ClickFix into its new campaigns. Like the previously mentioned campaigns, candidates are lured to fake interview websites crafted using ReactJS, which contain dynamic content loaded from JavaScript files that replicate authentic interviews. When applicants are requested to enable their camera, a dialogue box appears during this ‘interview’ displaying a fake pop-up error message stating that access to a user’s camera or microphone is currently blocked. The message says that the problem can be remediated with a user action of downloading drivers. 

Unresolved Issues 

What happens next in the attack is contingent upon the operating system in use. Needless to say, the unresolved ‘issues’ don’t get resolved… 

For macOS users, a Bash script named coremedia.sh downloads and extracts malicious files while creating a launch agent plist file for persistence then a stealer named FrostyFerret retrieves system passwords. Finally, Go malware designed for remote control and data theft, which Sekoia has coined GolangGhost, is deployed. 

Windows users experience a different process in which a Visual Basic Script (VBS) downloads a NodeJS-based payload called nvidia.js that extracts malicious files. Persistence here is established via registry keys before GolangGhost is launched through a batch file. 

Feedback 

Roger Grimes, Data-driven Defence Evangelist at KnowBe4, provided expert insight into the scale of these ‘fake interview’ style operations. “There are currently tens of thousands of innocent people responding to fake employer ads, which will either end up harming themselves financially, harming their current employer, or both. This is a big, big problem that is aggravated because most victims, people and organisations, don’t want to talk about what happened. It allows the damage to be even more widespread. 

Commenting on how the Lazarus group has pivoted into targeting non-technical roles with these scams, Dr Martin Kraemer, a Security Awareness Advocate also operating at KnowBe4, believes this approach will become the new normal. “The Lazarus group has developed the toolkit to target non-technical roles, and this capability will stay. In this case, script execution can be deactivated and deployment of the malware stopped. In any case, we must raise awareness of these types of threats, where a new job becomes the bait, and your employees turn into victims.” 

Actionable Steps 

One of the most concerning aspects of this style of ClickFake Interview is how, through targeting industries like crypto, prospective candidates in this field will most likely be less security-savvy than previously targeted sectors such as software developers and engineers. This makes these potential victims less likely to spot the signs of social engineering or even less likely to detect malicious commands. It is essential, therefore, that individuals in the cryptocurrency space stay vigilant as it is being targeted more frequently. Specifically, in relation to upcoming interviews, seek authentication through exploring official channels, and never click on links that aren’t from trusted sources. 

Adam Parlett
Adam Parlett

Adam Parlett is a cybersecurity marketing professional who has been working as a project manager at Bora for over two years. A Sociology graduate from the University of York, Adam enjoys the challenge of finding new and interesting ways to engage audiences with complex Cybersecurity ideas and products.

  • Adam Parlett
    Apache Tomcat Under Siege 2: Well-Hidden Payload
  • Adam Parlett
    NIST Adds SandboxAQ’s HQC as Their Newest PQC Standard
  • Adam Parlett
    Policy Statement Sheds Light on Upcoming UK Cybersecurity Bill
  • Adam Parlett
    PAC Report Highlights the Challenges Facing UK AI Growth Plan

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Ad Fraud is Much More Than a Marketing Problem

March 6, 20265 Mins Read

AI Is Making Social Engineering Harder to Detect—But We’re Still Training People Like It’s 2015

March 5, 20266 Mins Read

Sextortion and the Psychology of Fear: How Scammers Are Targeting Teenagers

January 28, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}