None
EN
DPRK Hackers Use ClickFix to Deliver BeaverTail Malware in Crypto Job Scams
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed leveraging ClickFix-style lures to deliver a known malware called BeaverTail and InvisibleFerret.
"The threat actor's targeting of marketing applicants and impersonation of a retail sector organization is noteworthy given BeaverTail distributors' usual focus on software developers and the cryptocurrency sector," Smith said.
"The BeaverTail variant associated with this campaign contains a simplified information stealer routine and targets fewer browser extensions," GitLab said.
North Korean hackers have a long history of attempting to gather threat intelligence to further their operations.
A Rust-based implant, CHILLYCHINO is a new addition to the threat actor's arsenal from June 2025.
['korean'
'beavertail'
'targets'
'threat'
'north'
'actors'
'hackers'
'deliver'
'job'
'campaign'
'crypto'
'scams'
'using'
'dprk'
'clickfix'
'infrastructure'
'malware']