Lazarus’ latest tactics: Deceptive development and ClickFix

2025-07-22 Gen Digital

https://www.gendigital.com/blog/insights/research/deceptive-nvidia-attack

Thumbnail for Lazarus’ latest tactics: Deceptive development and ClickFix

GenDigital observed a multi-stage DeceptiveDevelopment-style attack chain that used a mock hiring assessment and fake camera-update flow to trick users into copying and running a malicious command disguised as an NVIDIA-related update. The infection downloaded and extracted an archive, launched an embedded Python environment through a VBS script, and ran heavily obfuscated Python code that the researchers say aligns with known Lazarus APT tactics. The payload chain stole browser and email credentials with WebBrowserPassView and MailPassView, installed MeshAgent for remote access, deployed a PyInstaller component for file and secret extraction via FTP, and harvested cryptocurrency-related browser extensions and local folders. Reported indicators include the assessment URL assessdome[.]com/invite/7e462f3c/8002565804, C2 metakenproxy[.]com:81, and hashes for the VBS script, Python script, credential tools, MeshAgent, and ChromeUpdate.exe. The activity matters for DPRK-focused tracking because it combines social engineering against job seekers or developers with credential theft, persistence, remote access, and cryptocurrency targeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 36541fad68e79cdedb965b1afcdc453… 2025-07-22 2025-12-17
HASH bc7bd27e94e24a301edb3d3e7fad982… 2025-07-22 2025-12-17
HASH 9757780860ec5637c412a8756f25c56… 2025-07-22 2025-07-22
HASH 00bef70cd031a830f2ee1ec4ce75094… 2025-07-22 2025-07-22
HASH 03ad194456951695eb4d4ceb40d9e52… 2025-07-22 2025-07-22
HASH 7013822c0a794712c5fe8f62c126e59… 2025-07-22 2025-07-22
DOMAIN assessdome.com 2025-07-22 2025-07-22
DOMAIN metakenproxy.com 2025-07-22 2025-07-22

Related Actors

Related Reports

« Back