Cyber Security News

New ClickFake Interview Attack Using ClickFix Technique to Deliver GolangGhost Malware

The Lazarus Group’s long-running recruitment lure has resurfaced as “ClickFake Interview”, anchored on the freshly registered waventic[.]com site.

Candidates progress through a slick JavaScript form that ends with a bogus webcam “driver” download, actually planting the cross-platform GolangGhost malware.

Sekoia.io threat-defence researchers noted that the operators recycled the “ClickFix” web template first profiled in March 2025, but have now integrated geolocation filters and CAPTCHA to deter casual scanning.

The analysts traced more than forty companion domains spawned since April, all funnelling traffic toward apply[.]waventic[.]com before serving a statically linked Go binary compiled for Windows, Linux and macOS.

Lure website (Source – Sekoia)

The reinvigorated social engineering loop leverages stolen LinkedIn profiles and Telegram channels to appear legitimate, then abuses browser push-notifications to prompt the file transfer.

Once executed, GolangGhost immediately contacts hard-coded C2 endpoints over TLS-wrapped WebSockets, exporting a full inventory of running processes and OS-level metadata within seconds.

Early telemetry shows finance and blockchain start-ups in Europe and Southeast Asia among the first victims, with several macOS arm64 hosts already leaking credential vaults.

Delivered as a self-contained Go executable, the sample often bypasses signature-based antivirus engines that treat it as benign build output.

Infection mechanism

At launch GolangGhost drops a per-user copy into the OS-specific autostart directory and registers persistence keys named “SysDrvX %RAND%”.

The binary’s minimal footprint stems from dynamic module loading, most capabilities are fetched on demand via base64-encoded gRPC blobs.

The following excerpt, recovered during sandboxing, shows the loader decompressing its plugin package:-

blob, _ := base64.StdEncoding.DecodeString(pkg)
r, _ := zlib.NewReader(bytes.NewReader(blob))
io.Copy(os.TempDir()+"/"+modName, r)
cmd := exec.Command(os.TempDir()+"/"+modName, "-m", "init")
cmd.Start()

Security teams should monitor outbound WebSocket traffic to unfamiliar domains and flag Go executables spawning shell processes outside the user profile.

Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -> Try ANY.RUN Now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

32 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

1 hour ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

1 hour ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

2 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

3 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago