Close Menu
Crypto Chain Post
    Trending

    Solana Escapes Selling As Overheated Price Cools Down

    June 19, 2025

    Nauru Hopes To Become Crypto Hub

    June 19, 2025

    Unlicensed Crypto Activity in Jordan Could Soon Carry Jail Time

    June 19, 2025

    ETF Inflows Nearly Halve as Bitcoin Slides Amid Market Caution

    June 19, 2025

    Luffa Forms a Big Partnership with Cdari to Fuel AI-Driven E-Commerce on Matchain (L2 on BNB Chain)

    June 19, 2025
    Facebook X (Twitter) Instagram TikTok Telegram
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    Thursday, June 19
    Crypto Chain Post
    Price Index Newsletter
    • Home
    • News
      • Bitcoin
      • Ethereum
      • Altcoin
    • Blockchain
    • Markets
    • NFTs
    • DeFi
    • Web3
    • Analysis
    • Metaverse
    • Resources
      • Price Index
      • Crypto Heatmap
      • Glossary
      • Exchange
      • Economic Calendar
    • More
      • GameFi
      • ICO
      • Legal
      • Security
    Crypto Chain Post
    Home » North Korean Hackers Target Crypto Job Seekers in India
    Analysis

    North Korean Hackers Target Crypto Job Seekers in India

    News RoomBy News RoomJune 19, 2025No Comments3 Mins Read

    Cisco Talos reported that a North Korean hacker group named “Famous Chollima” has been focusing attacks on crypto job applicants in India. This group apparently has no direct connection to Lazarus.

    At the moment, it’s difficult to determine if these efforts were petty thefts or preliminary groundwork for larger attacks. Job seekers in the crypto industry should exercise caution moving forward.

    North Korea’s Crypto Hacks Continue

    North Korea’s Lazarus Group has a formidable reputation for crypto crime, perpetrating the greatest hack in the industry’s history. However, it’s not the country’s only Web3 criminal enterprise, as North Korea has a huge presence in DeFi.

    Cisco Talos identified some recent criminal activities in India that are taking a different approach to crypto theft:

    Reports suggest that Famous Chollima isn’t new; it’s been functioning since mid-2024 or earlier. In several recent incidents, North Korean hackers have attempted to infiltrate US-based crypto firms like Kraken by applying for open job listings.

    Famous Chollima did the reverse, luring potential workers with phony applications.

    “These campaigns include… creating fake job advertisements and skill-testing pages. In the latter, users are instructed to copy and paste a malicious command line in order to install drivers necessary to conduct the final skill-testing stage. [Affected users are] predominantly in India,” the firm claimed.

    Next to Lazarus’ formidable reputation, Famous Chollima’s phishing efforts seem much clumsier. Cisco claimed that the group’s fake applications would always mimic famous crypto firms.

    These lures did not use any of the real companies’ actual branding, asking questions that were hardly relevant to the supposed jobs in question.

    Fake Robinhood Application Used in Hacks. Source: Cisco Talos

    Swallowing the Bait

    Victims are lured through fake recruitment sites posing as well-known tech or crypto firms. After filling out applications, they are invited to a video interview.

    During this process, the site asks them to run command-line instructions—claimed to be for installing video drivers—which actually download and install malware.

    Once installed, PylangGhost gives attackers full control of the victim’s system. It steals login credentials, browser data, and crypto wallet information, targeting over 80 popular extensions like MetaMask, Phantom, and 1Password.

    Recently, after foiling a malware attack, BitMEX claimed that Lazarus uses at least two teams: a low-skill team to initially breach security protocols and a high-skill team to conduct subsequent thefts. Perhaps this is a common practice in North Korea’s hacking community.

    Unfortunately, it’s difficult to make any firm conclusions without speculating. Does North Korea want to hack these applicants to better pose as crypto industry job seekers?

    Uers should be cautious of unsolicited job offers, avoid running unknown commands, and secure their systems with endpoint protection, MFA, and browser extension monitoring.

    Always verify the legitimacy of recruitment portals before sharing any sensitive information.

    Read the full article here

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related News

    Andrew Tate’s crypto is about to hit a record low

    June 19, 2025

    Pi Network Faces Migration Chaos Ahead of June 28 Upgrade

    June 19, 2025

    SUI Reverses After Wild Swings; Trading Volume Spikes 11% Above 30-Day Average

    June 19, 2025

    Bitcoin Might Be Flat, But Traders Have Their Eyes on This Shiny New Token: Analysis

    June 19, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top News

    Nauru Hopes To Become Crypto Hub

    June 19, 2025

    Unlicensed Crypto Activity in Jordan Could Soon Carry Jail Time

    June 19, 2025

    ETF Inflows Nearly Halve as Bitcoin Slides Amid Market Caution

    June 19, 2025
    Advertisement
    Demo
    Crypto Chain Post
    • Home
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2025 Crypto Chain Post. All Rights Reserved.

    71-75 Shelton Street, Covent Garden, London United Kingdom, WC2H 9JQ

    Type above and press Enter to search. Press Esc to cancel.