故障修复之下的陷阱:Lazarus(APT-Q-1)近期利用 ClickFix 手法的攻击分析

2025-08-28 Qianxin The Trap Behind Troubleshooting: Analysis of Recent Lazarus (APT-Q-1) Attacks Using ClickFix Techniques

https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247515797&idx=1&sn=63eb2627f65397d704d187273c6cdce4&chksm=ea6649e2dd11c0f497ca57cf52676a9a764f28e587017e14fc850034ca8518c9f4ef46219824

Thumbnail for 故障修复之下的陷阱:Lazarus(APT-Q-1)近期利用 ClickFix 手法的攻击分析

Qianxin attributes a recent ClickFix campaign to Lazarus, tracked internally as APT-Q-1, based on overlap with prior Lazarus reporting and deployment of BeaverTail and InvisibleFerret. The campaign uses fake recruiting and interview sites to persuade victims to run supposed Nvidia or camera-driver fixes, while the downloaded packages install malicious tooling on Windows and macOS. On Windows, ClickFix-1.bat retrieves nvidiaRelease.zip from driverservices.store, runs VBS and batch scripts, installs or uses Node.js, launches BeaverTail from main.js, adds registry persistence, and on Windows 11 executes a drvUpdate.exe backdoor. BeaverTail contacts C2 such as 45.159.248.110 or 45.89.53.54 and can deploy InvisibleFerret, while drvUpdate.exe communicates with 103.231.75.101:8888 and supports device collection, command execution, file write, sleep, and file read functions. The macOS chain uses arm64-fixer-style packages and LaunchAgents persistence to run the same BeaverTail component, showing the social-engineering flow was adapted across platforms.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6175efd148a89ca61b6835c77acc7a8d 2025-08-28 2026-01-14
HASH 983a8a6f4d0a8c887536f5787a6b01a2 2025-08-28 2026-01-14
HASH f9e18687a38e968811b93351e9fca089 2025-08-28 2026-01-14
HASH 8c274285c5f8914cdbb090d72d1720d3 2025-08-28 2026-01-14
HASH 3ef7717c8bcb26396fc50ed92e812d13 2025-08-28 2026-01-14
HASH 15e48aef2e26f2367e5002e6c3148e1f 2025-08-28 2026-01-14
HASH 13400d5c844b7ab9aacc81822b1e7f02 2025-08-28 2026-01-14
HASH a4e58b91531d199f268c5ea02c7bf456 2025-08-28 2026-01-14
HASH b52e105bd040bda6639e958f7d9e3090 2025-08-28 2026-01-14
HASH cdf296d7404bd6193514284f021bfa54 2025-08-28 2026-01-14
HASH cbd183f5e5ed7d295d83e29b62b15431 2025-08-28 2026-01-14
URL https://driverservices.store/vi… 2025-08-28 2026-01-14
URL https://driverservices.store/vi… 2025-08-28 2026-01-14
URL https://block-digital.online/dr… 2025-08-28 2026-01-14
URL https://driverservices.store/vi… 2025-08-28 2026-01-14
URL https://driverservices.store/vi… 2025-08-28 2026-01-14
DOMAIN block-digital.online 2025-08-28 2026-01-14
DOMAIN driverservices.store 2025-08-28 2026-01-14
IPv4 103.231.75.101 2025-08-28 2026-01-14
IPv4 45.89.53.54 2025-08-28 2026-01-14
IPv4 45.159.248.110 2025-08-28 2026-01-14
HASH a009cd35850929199ef60e71bce86830 2025-08-28 2025-08-28
HASH b73fd8f21a2ed093f8caf0cf4b41aa4d 2025-08-28 2025-08-28
HASH 5e698d6f14e10616b0dbb1496e574a91 2025-08-28 2025-08-28
HASH d9fb02481d1df9f93b7d8e84dc7e097f 2025-08-28 2025-08-28
HASH 17eb90ac00007154a6418a91bf8da9c7 2025-08-28 2025-08-28

Related Actors

Related Reports

« Back