PULSE NAME
Traps Beneath Fault Repair: Analysis of Recent Attacks Using ClickFix Technique
WHITE Lazarus AlienVault 2025-09-01 Modified: 2025-10-01
33
IOCs
MEDIUM VOLUME
Lazarus, an APT group with suspected East Asian origins, has recently employed the ClickFix social engineering technique in their phishing attacks. The group, known for targeting financial institutions and cryptocurrency exchanges, now uses fake job opportunities to lure victims to interview websites. These sites prompt users to 'fix' non-existent camera issues, tricking them into downloading malware disguised as Nvidia software updates. The malware deploys a Node.js environment and executes BeaverTail, a common Lazarus tool. On Windows 11 systems, an additional backdoor (drvUpdate.exe) is installed. The attack also affects macOS users. The malware establishes persistence and connects to command and control servers for further instructions and data exfiltration.
Indicators of Compromise (2 / 33 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 61525e782cde36d5ed807084f6427d06f2915114b8dc7b33febd3b2566115541 2025-09-01
FileHash-SHA256 979d20f83f4e992f96f6a23b5119e84959ce82f4a7d4af78b4094b87a05b6260 2025-09-01