故障修复之下的陷阱:Lazarus(APT-Q-1)近期利用 ClickFix 手法的攻击分析
2025-08-28 • Qianxin • The Trap Behind Troubleshooting: Analysis of Recent Lazarus (APT-Q-1) Attacks Using ClickFix Techniques •
Qianxin attributes a recent ClickFix campaign to Lazarus, tracked internally as APT-Q-1, based on overlap with prior Lazarus reporting and deployment of BeaverTail and InvisibleFerret. The campaign uses fake recruiting and interview sites to persuade victims to run supposed Nvidia or camera-driver fixes, while the downloaded packages install malicious tooling on Windows and macOS. On Windows, ClickFix-1.bat retrieves nvidiaRelease.zip from driverservices.store, runs VBS and batch scripts, installs or uses Node.js, launches BeaverTail from main.js, adds registry persistence, and on Windows 11 executes a drvUpdate.exe backdoor. BeaverTail contacts C2 such as 45.159.248.110 or 45.89.53.54 and can deploy InvisibleFerret, while drvUpdate.exe communicates with 103.231.75.101:8888 and supports device collection, command execution, file write, sleep, and file read functions. The macOS chain uses arm64-fixer-style packages and LaunchAgents persistence to run the same BeaverTail component, showing the social-engineering flow was adapted across platforms.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6175efd148a89ca61b6835c77acc7a8d | 2025-08-28 | 2026-01-14 |
| HASH | 983a8a6f4d0a8c887536f5787a6b01a2 | 2025-08-28 | 2026-01-14 |
| HASH | f9e18687a38e968811b93351e9fca089 | 2025-08-28 | 2026-01-14 |
| HASH | 8c274285c5f8914cdbb090d72d1720d3 | 2025-08-28 | 2026-01-14 |
| HASH | 3ef7717c8bcb26396fc50ed92e812d13 | 2025-08-28 | 2026-01-14 |
| HASH | 15e48aef2e26f2367e5002e6c3148e1f | 2025-08-28 | 2026-01-14 |
| HASH | 13400d5c844b7ab9aacc81822b1e7f02 | 2025-08-28 | 2026-01-14 |
| HASH | a4e58b91531d199f268c5ea02c7bf456 | 2025-08-28 | 2026-01-14 |
| HASH | b52e105bd040bda6639e958f7d9e3090 | 2025-08-28 | 2026-01-14 |
| HASH | cdf296d7404bd6193514284f021bfa54 | 2025-08-28 | 2026-01-14 |
| HASH | cbd183f5e5ed7d295d83e29b62b15431 | 2025-08-28 | 2026-01-14 |
| URL | https://driverservices.store/vi… | 2025-08-28 | 2026-01-14 |
| URL | https://driverservices.store/vi… | 2025-08-28 | 2026-01-14 |
| URL | https://block-digital.online/dr… | 2025-08-28 | 2026-01-14 |
| URL | https://driverservices.store/vi… | 2025-08-28 | 2026-01-14 |
| URL | https://driverservices.store/vi… | 2025-08-28 | 2026-01-14 |
| DOMAIN | block-digital.online | 2025-08-28 | 2026-01-14 |
| DOMAIN | driverservices.store | 2025-08-28 | 2026-01-14 |
| IPv4 | 103.231.75.101 | 2025-08-28 | 2026-01-14 |
| IPv4 | 45.89.53.54 | 2025-08-28 | 2026-01-14 |
| IPv4 | 45.159.248.110 | 2025-08-28 | 2026-01-14 |
| HASH | a009cd35850929199ef60e71bce86830 | 2025-08-28 | 2025-08-28 |
| HASH | b73fd8f21a2ed093f8caf0cf4b41aa4d | 2025-08-28 | 2025-08-28 |
| HASH | 5e698d6f14e10616b0dbb1496e574a91 | 2025-08-28 | 2025-08-28 |
| HASH | d9fb02481d1df9f93b7d8e84dc7e097f | 2025-08-28 | 2025-08-28 |
| HASH | 17eb90ac00007154a6418a91bf8da9c7 | 2025-08-28 | 2025-08-28 |