Reports Emerge That North Korean Hackers Are Expanding Their Malware Methods
For years, the Democratic People’s Republic of Korea (DPRK or North Korea) “Contagious Interview” campaign relied on fake developer job postings to lure targets into running malware like BeaverTail and InvisibleFerret. I...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
For years, the Democratic People’s Republic of Korea (DPRK or North Korea) “Contagious Interview” campaign relied on fake developer job postings to lure targets into running malware like BeaverTail and InvisibleFerret. It has recently evolved.
The DPRK government hacking collective, which has codenames including Lazarus and Hidden Cobra, has for several years targeted crypto companies, protocols, and holders, as theft targets. They are behind some of the largest crypto heists in history, but are known for casting a wide net and having a variety of hacking methods, targeting big and little fish. They have become well-known for their malware deployment infrastructure, which targets victims looking for jobs at crypto companies. Once a victim is duped into applying for a fake job, the trap is set.
Victims would be tricked into uploading a fake “introductory video” and, after encountering a false microphone error, are told to paste a “quick fix” command into their terminal. This command quietly delivered malware that gave attackers remote access and let them siphon sensitive data and crypto funds.
But in late May 2025, researchers observed a major shift. According to GitLab security researcher Oliver Smith, the ClickFix variant now uses the same technique to target cryptocurrency trader roles, marketing and sales positions at Web3 organizations, and even staff at a U.S. e-commerce retailer.
This means non-technical employees — people far less likely to suspect a terminal “fix” command — are now firmly in the hackers’ crosshairs.
How to Spot the New “ClickFix Interview” ScamUnlike older lures, ClickFix targets people with interview tasks like uploading files or joining a call. When the system generates a fake microphone or camera error, victims are told to paste a short terminal command as a “solution.” That one step silently installs BeaverTail malware, which enables full device compromise and crypto theft.
Red Flags to Watch For:
- Interview tasks requiring terminal commands
- Requests to disable or “fix” audio/video drivers during calls.
- Repeated urging to install one-off scripts from unfamiliar domains.
This new wave of hacks is dangerous as it evidences:
- Extending targets: With marketing and sales staff targeted, attackers exploit roles with weaker security habits.
- Direct investor targeting: GitLab observed phishing tied to “invitations to invest at a Web3 organization”, suggesting retail investors themselves may also be lured.
BeaverTail functions as a downloader/infostealer that can harvest browser-stored credentials and cryptocurrency wallet data and then pull down InvisibleFerret, a Python backdoor for persistence and remote control. Palo Alto Networks’ Unit 42 has tracked a Qt-based, cross-platform BeaverTail build and documented targeting of 13 crypto wallet extensions.
The broader cluster—linked to Lazarus and related DPRK activity—has also abused open-source registries. Datadog Security Labs tied malicious npm packages to BeaverTail within the Contagious Interview ecosystem. Sekoia’s March 2025 reporting describes a “ClickFake Interview” variant that deploys backdoors on both Windows and macOS while shifting targets beyond developers.
Why This Matters to Crypto Teams and InvestorsDPRK’s crypto operations are not theoretical. In February 2025, the FBI issued a PSA attributing the $1.5 billion Bybit theft to DPRK actors known as TraderTraitor, underscoring the scale and sophistication of state-directed financial cybercrime.
The U.S. government has long warned the crypto sector about DPRK tradecraft (e.g., CISA AA22-108A), and OFAC maintains sanctions on DPRK cyber units and facilitators.
For Web3 employers, the target profile expansion (marketing, sales, trading) widens the attack surface to teams that may lack secure-coding instincts or hardened dev environments. For individuals, the one-liner “fix” during a live interview remains a potent social-engineering trick—especially when paired with compiled payloads that avoid interpreter dependencies and some detections.
Conclusion: From Targeted Developers to Mass RiskThe latest findings show North Korea’s hacker units are not standing still. They are expanding beyond developers, refining their malware with ClickFix lures, and sustaining activity by rapidly replacing their infrastructure.
For the crypto industry, the lesson is clear: security is no longer just an IT problem. Every employee, every applicant, and even investors themselves are potential targets. Organizations that fail to adapt their defenses risk becoming the next headline.
Why this matters
This research story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Brave New CoinRelated market context
MetaMask Exits Ethereum Validators After Security Incident Hits Staking Infrastructure
Key Takeaways: MetaMask is addressing a security incident to its infrastructure of which it is unaware. According to the company,...
Chainalysis links most of the stolen XRP in $387M Bitget hack to North Korea
The Bitget hack highlights escalating cyber threats from North Korea, stressing the need for enhanced security measures and rapid...
Crypto scammers hijack Microsoft’s official X account to push a fake Clippy token
The incident underscores the vulnerability of corporate social media accounts to scams, highlighting the need for enhanced securit...
Ripple-Backed XRP Treasury Evernorth Wins Shareholder Vote, Heads to Nasdaq Next Week
Evernorth, the XRP treasury company backed by Ripple, is on track to start trading on Nasdaq on Oct. 8 after shareholders of its b...
Jack Dorsey’s Block Launches Campaign To Get People Spending Bitcoin
Bitcoin Magazine Jack Dorsey’s Block Launches Campaign To Get People Spending Bitcoin Jack Dorsey’s Block continues the push to ma...
Bloomberg Launches $300B Stablecoin Dashboard With Hourly Onchain Data on Terminal
Key Takeaways: Allium has now provided Bloomberg Terminal with hourly stablecoin data. The dashboard includes over 98% of the stab...