Close Menu
Crypto Chain Post
    Trending

    Japanese Retailer Mac House Makes Bold $12M Crypto Investment Move

    June 20, 2025

    12% of users opt for LTC or TRX to pay for VPN services in crypto

    June 20, 2025

    Binance Pauses Crypto Operations for Zilliqa Upgrade

    June 20, 2025

    Pepe Reclaims $0.000010 as Bullish Signals Build: Is a Reversal Incoming?

    June 20, 2025

    Ripple and SEC Seek Relief Modification In XRP Lawsuit, Lawyer Explains

    June 20, 2025
    Facebook X (Twitter) Instagram TikTok Telegram
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    Friday, June 20
    Crypto Chain Post
    Price Index Newsletter
    • Home
    • News
      • Bitcoin
      • Ethereum
      • Altcoin
    • Blockchain
    • Markets
    • NFTs
    • DeFi
    • Web3
    • Analysis
    • Metaverse
    • Resources
      • Price Index
      • Crypto Heatmap
      • Glossary
      • Exchange
      • Economic Calendar
    • More
      • GameFi
      • ICO
      • Legal
      • Security
    Crypto Chain Post
    Home » North Korea Targets Crypto Jobs With New Malware
    News

    North Korea Targets Crypto Jobs With New Malware

    News RoomBy News RoomJune 20, 2025No Comments3 Mins Read

    A North Korean-aligned threat actor has been targeting job seekers in the crypto industry with new malware that is designed to steal passwords for crypto wallets and password managers.

    Cisco Talos reported on Wednesday that it found a new Python-based remote access trojan (RAT) it called “PylangGhost,” linking the malware to a North Korean-affiliated hacking collective called “Famous Chollima,” also known as “Wagemole.”

    The hacking group has been targeting job seekers and employees with cryptocurrency and blockchain experience, primarily in India, with the attacks carried out through fake job interview campaigns using social engineering.

    “Based on the advertised positions, it is clear that the Famous Chollima is broadly targeting individuals with previous experience in cryptocurrency and blockchain technologies.” 

    Fake job sites and tests a cover for malware

    The attackers create fraudulent job sites that impersonate legitimate companies, such as Coinbase, Robinhood and Uniswap, and victims are guided through a multi-step process. 

    This includes initial contact from fake recruiters who send invites to skill-testing websites where the information gathering occurs.

    Sample of fake job website. Source: Cisco Talos

    Next, the victims are lured into enabling video and camera access for fake interviews during which they are tricked into copying and executing malicious commands under the pretense of installing updated video drivers, resulting in the compromise of their device. 

    Payload targets crypto wallets 

    PylangGhost is a variant of the previously documented GolangGhost RAT, and shares similar functionality, Cisco Talos said.

    Upon execution, the commands enable remote control of the infected system and the theft of cookies and credentials from over 80 browser extensions, it reported. 

    These include password managers and cryptocurrency wallets, including MetaMask, 1Password, NordPass, Phantom, Bitski, Initia, TronLink and MultiverseX. 

    Instructions to download the payload. Source: Cisco Talos

    Multitasking malware 

    The malware can carry out other tasks and execute numerous commands, including taking screenshots, managing files, stealing browser data, collecting system information and maintaining remote access to infected systems.

    Related: Scammers use fake crypto jobs, ‘GrassCall’ meeting app to drain wallets

    The researchers also noted that it was unlikely that the threat actors used an artificial intelligence large language model to help write the code, based on the comments made within it.

    Fake job lures not new 

    It is not the first time North Korean-linked hackers have used fake jobs and interviews to lure their victims. 

    In April, hackers linked to the $1.4 billion Bybit heist were targeting crypto developers using fake recruitment tests infected with malware. 

    Magazine: Arthur Hayes doesn’t care when his Bitcoin predictions are totally wrong

    Read the full article here

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related News

    Japanese Retailer Mac House Makes Bold $12M Crypto Investment Move

    June 20, 2025

    12% of users opt for LTC or TRX to pay for VPN services in crypto

    June 20, 2025

    Retail Bullish Sentiment Drops to Lowest Level Since Tariff Events

    June 20, 2025

    Solo Bitcoin Miner Wins $330K Bitcoin Block in June 2025

    June 20, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top News

    12% of users opt for LTC or TRX to pay for VPN services in crypto

    June 20, 2025

    Binance Pauses Crypto Operations for Zilliqa Upgrade

    June 20, 2025

    Pepe Reclaims $0.000010 as Bullish Signals Build: Is a Reversal Incoming?

    June 20, 2025
    Advertisement
    Demo
    Crypto Chain Post
    • Home
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Crypto Chain Post. All Rights Reserved.

    71-75 Shelton Street, Covent Garden, London United Kingdom, WC2H 9JQ

    Type above and press Enter to search. Press Esc to cancel.