Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed leveraging ClickFix-style lures to deliver a known malware called BeaverTail and InvisibleFerret. "The threat actor's targeting of marketing applicants and impersonation of a retail sector organization is noteworthy given BeaverTail distributors' usual focus on software developers and the cryptocurrency sector," Smith said. "The BeaverTail variant associated with this campaign contains a simplified information stealer routine and targets fewer browser extensions," GitLab said. North Korean hackers have a long history of attempting to gather threat intelligence to further their operations. A Rust-based implant, CHILLYCHINO is a new addition to the threat actor's arsenal from June 2025.