ClickFake Interview is a North Korea-aligned social-engineering and malware delivery cluster associated with fake job-interview and fake meeting lures, and is linked in reporting to broader DPRK cryptocurrency-targeting activity overlapping with BlueNoroff and related Lazarus ecosystem operations. The cluster uses ClickFix-style deception, including prompts that trick targets into running malicious commands under the pretext of fixing camera, microphone, or conferencing problems during staged remote interviews or meetings. The operation has targeted individuals in the cryptocurrency and Web3 ecosystem, including employees with access or influence over digital-asset environments. Tradecraft includes outreach through trusted or compromised contacts on Telegram, scheduling through fake meeting invitations, impersonation of videoconferencing platforms such as Zoom and Microsoft Teams, and selective victim qualification before payload delivery. Observed phishing workflows collect victim identity details, request webcam access, fingerprint browsers, and enumerate installed cryptocurrency-wallet extensions to identify higher-value targets. The cluster’s attack chains support both Windows and macOS. On Windows, observed delivery has used PowerShell and VBScript-based loaders, including actions intended to weaken host defenses and prepare for follow-on payloads. On macOS, observed chains have used shell scripts and installer-themed lures to deploy stealers and backdoors. Reported post-compromise behaviors across related activity include theft of Telegram session data, collection of cryptocurrency-wallet intelligence, exfiltration of host metadata, keylogging, screen and clipboard monitoring, download-and-execute of additional payloads, and broader post-exploitation through remote command execution and process injection. The social-engineering component is notably sophisticated. Operators have used staged fake meetings, fake participant messages, and deepfake or AI-enhanced video elements to increase credibility and pressure victims into executing malicious steps. The activity shows ongoing development, with multiple phishing-kit iterations observed over a short period, indicating active refinement of lures, platform impersonation, and victim-selection logic. ClickFake Interview is best understood as a DPRK-aligned intrusion cluster focused on financially motivated compromise of cryptocurrency-sector personnel through highly tailored social engineering, credential and session theft, malware deployment, and intelligence gathering on digital-asset holdings.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related North Korea-aligned threat cluster tracked for using ClickFix-like lures themed around fixing camera or audio issues to trick targets into executing malicious commands.
Evolved North Korea-linked job-lure campaign using fake job ads and fake assessment sites to trick applicants into copying/running malicious commands (camera/mic 'fix' pretext), delivering cross-platform malware (including PylangGhost).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.