Lazarus’ latest tactics: Deceptive development and ClickFix
2025-07-22 • Gen Digital •
https://www.gendigital.com/blog/insights/research/deceptive-nvidia-attack
GenDigital observed a multi-stage DeceptiveDevelopment-style attack chain that used a mock hiring assessment and fake camera-update flow to trick users into copying and running a malicious command disguised as an NVIDIA-related update. The infection downloaded and extracted an archive, launched an embedded Python environment through a VBS script, and ran heavily obfuscated Python code that the researchers say aligns with known Lazarus APT tactics. The payload chain stole browser and email credentials with WebBrowserPassView and MailPassView, installed MeshAgent for remote access, deployed a PyInstaller component for file and secret extraction via FTP, and harvested cryptocurrency-related browser extensions and local folders. Reported indicators include the assessment URL assessdome[.]com/invite/7e462f3c/8002565804, C2 metakenproxy[.]com:81, and hashes for the VBS script, Python script, credential tools, MeshAgent, and ChromeUpdate.exe. The activity matters for DPRK-focused tracking because it combines social engineering against job seekers or developers with credential theft, persistence, remote access, and cryptocurrency targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 36541fad68e79cdedb965b1afcdc453… | 2025-07-22 | 2025-12-17 |
| HASH | bc7bd27e94e24a301edb3d3e7fad982… | 2025-07-22 | 2025-12-17 |
| HASH | 9757780860ec5637c412a8756f25c56… | 2025-07-22 | 2025-07-22 |
| HASH | 00bef70cd031a830f2ee1ec4ce75094… | 2025-07-22 | 2025-07-22 |
| HASH | 03ad194456951695eb4d4ceb40d9e52… | 2025-07-22 | 2025-07-22 |
| HASH | 7013822c0a794712c5fe8f62c126e59… | 2025-07-22 | 2025-07-22 |
| DOMAIN | assessdome.com | 2025-07-22 | 2025-07-22 |
| DOMAIN | metakenproxy.com | 2025-07-22 | 2025-07-22 |