PULSE NAME
Traps Beneath Fault Repair: Analysis of Recent Attacks Using ClickFix Technique
WHITE Lazarus AlienVault 2025-09-01 Modified: 2025-10-01
33
IOCs
MEDIUM VOLUME
Lazarus, an APT group with suspected East Asian origins, has recently employed the ClickFix social engineering technique in their phishing attacks. The group, known for targeting financial institutions and cryptocurrency exchanges, now uses fake job opportunities to lure victims to interview websites. These sites prompt users to 'fix' non-existent camera issues, tricking them into downloading malware disguised as Nvidia software updates. The malware deploys a Node.js environment and executes BeaverTail, a common Lazarus tool. On Windows 11 systems, an additional backdoor (drvUpdate.exe) is installed. The attack also affects macOS users. The malware establishes persistence and connects to command and control servers for further instructions and data exfiltration.
Indicators of Compromise (2 / 33 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 10c967386460027e7492b6138502ab61ca828e37 2025-09-01
FileHash-SHA1 792afe735d6d356fd30d2e7d0a693e3906decca7 2025-09-01