ClickFix/SmartApeSG/Lazarus/APT37 evolving
Key Questions
What tactics are North Korean groups like Lazarus and APT37 using in recent ClickFix campaigns?
They deploy ClickFix via AI-generated Zoom/Teams/Meet lures and fake job offers on LinkedIn and GitHub targeting crypto executives, combined with trojanized apps, supply-chain attacks, and clipboard hijacks for credential and wallet theft. New variants include a fake Claude Code installer via Google Sites using steganography and in-memory execution, plus NarwhalRAT campaigns against South Korea with LNK shortcuts and Python loaders disguised in local app directories.
How has AI contributed to the rise in these phishing and impersonation attacks?
AI has driven a 1265% surge in attacks, enabling deepfakes, personalized spear-phishing that now comprises 40% of scam messages, and rapid creation of lures mimicking brands like ChatGPT or Claude. Reports show 82.6% of phishing now uses AI, with techniques like user-agent fingerprinting for platform-specific payloads and HTML comment stuffing to evade AI/ML detection.
What new evasion and delivery methods are expanding NK threat actor capabilities?
Recent additions include APT-C-60's multi-stage chains abusing Proton Drive, jsDelivr, and GitLab, GitHub impersonation with libcurl side-loading, Microsoft Teams vishing delivering EtherRAT, and adaptive phishing via FleetDeck or Tiflux. Operation BlueDash further demonstrates RMM tools like Level and ScreenConnect delivered through fake Teams updates with multi-RMM redundancy.
NK Lazarus/BlueNoroff/APT37 deploys ClickFix Remcos/MacSync/LNK-ZIP Python backdoor via AI Zoom/Teams/Meet and fake-job lures (LinkedIn/GitHub) tricking crypto execs. Adds trojanized apps, supply-chain, clipboard hijacks for creds/wallet exfil. 1265% AI surge, deepfakes; $3B+ thefts. PhishSigma++/layered >99% effective. New: Fake Claude Code installer via Google Sites (steganography, in-memory execution) expands lure diversity. Recent Microsoft blog details AI-branded phishing (ChatGPT, Claude) with multi-stage redirects, CAPTCHA, and credential/credit card theft, including 8% financial services targeting in Claude campaign. New: APT37 NarwhalRAT campaign targeting South Korea with LNK shortcuts, Python loaders, and local app camouflage (naverwhale directory, KakaoTalk filter) – detailed technical analysis adds to NK TTP catalog. Latest: Detailed analysis of NarwhalRAT reveals multi-stage LNK-to-Python loader with in-memory execution and pCloud dead-drop C2, expanding NK evasion techniques. New: AI-Powered Impersonation Attacks article adds taxonomy of six AI impersonation types, crypto CEO deepfake case, and ClickFix 517% rise. Red team report demonstrates AI phishing + ClickFix + MFA bypass chain in 5 minutes, reinforcing urgency for layered defenses. New: ScarCruft/APT37 enterprise targeting campaign (Threat Advisory) adds to NK social engineering TTPs, though financial sector specificity not confirmed. A recent before-and-after AI impact study shows per-incident handling improved 16% but overall costs rose 14% due to volume surge; personalized attacks now take minutes. New: Adaptive phishing campaigns using user-agent fingerprinting to deliver platform-specific payloads (FleetDeck for macOS, Tiflux for Windows) – raises detection bar for mixed-device financial orgs. Cofense research confirms this trend with technical analysis. New: ClickFix expands to macOS via AppleScript, achieving 14.9% initial access share and 28% defense evasion; malware churn (BaoLoader/Remcos out, Gamarue/Raspberry Robin in); Qilin ransomware 700 victims and SMB lateral movement shift. New: A peer-reviewed study (arXiv 2411.13860) confirms AI-driven spear-phishing surge (14-fold increase, now 40% of scam messages), validated on human subjects, providing empirical evidence for the scale of AI automation in personalized attacks. New: AI-Speed Attacks article reports 82.6% of phishing attacks now use AI, and emphasizes that verification procedures must be rethought as human judgment can no longer reliably detect AI-crafted lures. New: Five Eyes AI warning and OALABS case of low-skill attacker using commercial AI to compromise 14 companies – AI lowering barrier to entry for system compromise and BEC. New: HTML comment stuffing evasion technique dilutes AI/ML signal density, challenging AI-only defenses. New: APT-C-60 campaign using Proton Drive, jsDelivr, GitLab, Codeberg to deliver SpyGlace via multi-stage LNK->mshta->git.exe chain, expanding legitimate service abuse for spear-phishing. New: GitHub impersonation campaign targeting fintech/crypto brands with infostealer via libcurl.dll side-loading and in-memory execution – adds to supply-chain abuse trend. New: Microsoft Teams vishing campaign delivers EtherRAT via fake IT support calls using AnyDesk, Node.js, MSI installers – adds to collaboration platform abuse trend. New: Concrete case of DPRK IT worker infiltration at Consensys/MetaMask – fake job hire with alias and GitHub handle, month-long access to core platform code (including fiat on-ramp). Validates supply-chain infiltration vector for crypto firms. New: Operation BlueDash deploys Level RMM and ScreenConnect via fake Teams updates, multi-RMM redundancy, Nigerian attribution, JIVS PhishKit, Kratos takedown – adds to RMM/collaboration platform abuse trend.