DPRK-linked actors have evolved their ClickFix social engineering campaigns, now targeting marketing and trading roles in cryptocurrency and retail sectors with BeaverTail and InvisibleFerret malware. The latest wave features compiled malware variants and new delivery tactics, including fake hiring platforms and password-protected archives. This marks a tactical shift to reach less technical targets and adapt to takedown efforts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
A large-scale attack abusing GitHub Pages was reported as delivering stealer malware to macOS users. The campaign was highlighted as a significant malware distribution operation affecting Macs.
Threat reporting cited collaboration between the Gamaredon and Turla groups. The relationship was presented as a notable attribution and operational development.
CISA released a malware analysis report covering a malicious listener targeting Ivanti Endpoint Manager Mobile. The publication provided official technical details on the malware and its targeting.
Satori Threat Intelligence issued an alert concerning SlopAds fraud operations. The alert was included among the notable threat developments current as of the reporting date.
Researchers reported on a FileFix campaign that employed steganography as part of its attack chain. The use of hidden content for delivery or evasion was noted as a key technical detail.
Reporting described the spread of the Shai-hulud worm against npm packages. The activity was highlighted as part of a broader pattern of attacks abusing open-source software distribution channels.
A major software supply chain incident compromised the Tinycolor npm package along with more than 40 related packages. The event was identified as one of the most significant malware and ecosystem threats covered in the reporting.
Researchers highlighted new Mustang Panda (Hive0154) activity involving the Toneshell backdoor and the SnakeDisk USB worm. The campaigns were cited as a significant ongoing malware development.
Security reporting identified a resurgence of the SmokeLoader malware as a notable development. The renewed activity was included among the major malware trends observed as of late September 2025.
Reporting noted that the North Korean operators quickly replaced malicious infrastructure after takedowns, indicating an adaptive and resilient campaign. The shift was described as reflecting increased sophistication and stronger financially motivated targeting.
The DPRK-linked campaigns adopted ClickFix-style infection chains to deliver malware including BeaverTail, InvisibleFerret, CHILLYCHINO, and FadeStealer. Operators also used compiled payloads, password-protected archives, GitHub-hosted infrastructure, and deepfake-enabled social engineering to improve delivery and evasion.
North Korean threat actors, including Lazarus subgroups and Kimsuky/APT43, broadened fake job-themed campaigns from software developers to marketing and trading roles in cryptocurrency and retail sectors. The activity used social engineering through fake hiring platforms and spear-phishing to reach a wider victim pool.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.