Close Menu
Crypto Chain Post
    Trending

    Binance Launches Crypto Inheritance Feature for Users’ Heirs

    June 19, 2025

    Bitcoin User Accidentally Sent $60,000 in Fees—Don’t Make the Same Mistake

    June 19, 2025

    Brazil’s Congress up in Arms Against ‘Flawed’ Cryptocurrency Tax Decree

    June 19, 2025

    Canadian Fintech LQwD Strengthens Bitcoin Holdings, Now Totals 166 BTC

    June 19, 2025

    DeFi at a crossroads: The SEC’s new stance could change everything

    June 19, 2025
    Facebook X (Twitter) Instagram TikTok Telegram
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    Thursday, June 19
    Crypto Chain Post
    Price Index Newsletter
    • Home
    • News
      • Bitcoin
      • Ethereum
      • Altcoin
    • Blockchain
    • Markets
    • NFTs
    • DeFi
    • Web3
    • Analysis
    • Metaverse
    • Resources
      • Price Index
      • Crypto Heatmap
      • Glossary
      • Exchange
      • Economic Calendar
    • More
      • GameFi
      • ICO
      • Legal
      • Security
    Crypto Chain Post
    Home » North Korean Hackers Target Crypto Job Seekers in India
    Analysis

    North Korean Hackers Target Crypto Job Seekers in India

    News RoomBy News RoomJune 19, 2025No Comments3 Mins Read

    Cisco Talos reported that a North Korean hacker group named “Famous Chollima” has been focusing attacks on crypto job applicants in India. This group apparently has no direct connection to Lazarus.

    At the moment, it’s difficult to determine if these efforts were petty thefts or preliminary groundwork for larger attacks. Job seekers in the crypto industry should exercise caution moving forward.

    North Korea’s Crypto Hacks Continue

    North Korea’s Lazarus Group has a formidable reputation for crypto crime, perpetrating the greatest hack in the industry’s history. However, it’s not the country’s only Web3 criminal enterprise, as North Korea has a huge presence in DeFi.

    Cisco Talos identified some recent criminal activities in India that are taking a different approach to crypto theft:

    Reports suggest that Famous Chollima isn’t new; it’s been functioning since mid-2024 or earlier. In several recent incidents, North Korean hackers have attempted to infiltrate US-based crypto firms like Kraken by applying for open job listings.

    Famous Chollima did the reverse, luring potential workers with phony applications.

    “These campaigns include… creating fake job advertisements and skill-testing pages. In the latter, users are instructed to copy and paste a malicious command line in order to install drivers necessary to conduct the final skill-testing stage. [Affected users are] predominantly in India,” the firm claimed.

    Next to Lazarus’ formidable reputation, Famous Chollima’s phishing efforts seem much clumsier. Cisco claimed that the group’s fake applications would always mimic famous crypto firms.

    These lures did not use any of the real companies’ actual branding, asking questions that were hardly relevant to the supposed jobs in question.

    Fake Robinhood Application Used in Hacks. Source: Cisco Talos

    Swallowing the Bait

    Victims are lured through fake recruitment sites posing as well-known tech or crypto firms. After filling out applications, they are invited to a video interview.

    During this process, the site asks them to run command-line instructions—claimed to be for installing video drivers—which actually download and install malware.

    Once installed, PylangGhost gives attackers full control of the victim’s system. It steals login credentials, browser data, and crypto wallet information, targeting over 80 popular extensions like MetaMask, Phantom, and 1Password.

    Recently, after foiling a malware attack, BitMEX claimed that Lazarus uses at least two teams: a low-skill team to initially breach security protocols and a high-skill team to conduct subsequent thefts. Perhaps this is a common practice in North Korea’s hacking community.

    Unfortunately, it’s difficult to make any firm conclusions without speculating. Does North Korea want to hack these applicants to better pose as crypto industry job seekers?

    Uers should be cautious of unsolicited job offers, avoid running unknown commands, and secure their systems with endpoint protection, MFA, and browser extension monitoring.

    Always verify the legitimacy of recruitment portals before sharing any sensitive information.

    Read the full article here

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related News

    Solana’s Weekly Losses Mount Up – Will SOL Price Slide Further?

    June 19, 2025

    Bearish Sentiment Rises, Will Key Support Levels Hold Strong?

    June 19, 2025

    Meta Pool Confirms ~$47,000 Exploit on Ethereum, mpETH Contract Paused for Investigation

    June 19, 2025

    Predicate, Paxos, and the policy layer

    June 19, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top News

    Bitcoin User Accidentally Sent $60,000 in Fees—Don’t Make the Same Mistake

    June 19, 2025

    Brazil’s Congress up in Arms Against ‘Flawed’ Cryptocurrency Tax Decree

    June 19, 2025

    Canadian Fintech LQwD Strengthens Bitcoin Holdings, Now Totals 166 BTC

    June 19, 2025
    Advertisement
    Demo
    Crypto Chain Post
    • Home
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Crypto Chain Post. All Rights Reserved.

    71-75 Shelton Street, Covent Garden, London United Kingdom, WC2H 9JQ

    Type above and press Enter to search. Press Esc to cancel.