BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Use Fake Crypto Jobs to Spread New RAT Malware

North Korean Hackers Use Fake Crypto Job Offers and Python Malware to Target Indian Job Seekers

  • A North Korean-linked Hacking group is using fake crypto job offers to target job seekers mainly in India.
  • The group deploys Python-based Malware, called “PylangGhost,” to steal credentials for crypto wallets and password managers.
  • Victims are directed to fake job sites and tricked into running harmful commands during bogus interview processes.
  • PylangGhost can steal browser cookies, manage files, take screenshots, and maintain remote access to compromised devices.
  • The attackers focus on individuals with experience in cryptocurrency and blockchain technologies.

A hacking group affiliated with North Korea has targeted job seekers in the cryptocurrency industry using a new malware called "PylangGhost," according to security researchers at Cisco Talos. The group, known as "Famous Chollima" or "Wagemole," has mainly focused its efforts on India by creating fake recruitment campaigns and job sites that imitate legitimate organizations, such as Coinbase and Robinhood, to steal information.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The attackers invite victims to participate in job interviews through fraudulent sites and require them to perform technical tasks that secretly install malware on their computers. Cisco Talos reported that this malware, written in Python, enables remote control of the infected device and specifically targets credentials stored in browser extensions, including crypto wallets like MetaMask and password managers such as 1Password and NordPass.

The malicious software, which is a variant of the previously observed GolangGhost RAT, can execute a range of commands once installed. "Based on the advertised positions, it is clear that the Famous Chollima is broadly targeting individuals with previous experience in cryptocurrency and blockchain technologies," the researchers said in their report. The trojan allows attackers to steal cookies and credentials from over 80 different browser extensions, as well as take screenshots, collect system information, and control files on the infected machines.

Victims are typically asked to enable video and camera access for fake interviews, then instructed to run commands under the pretense of installing video drivers. These actions result in system compromise and data theft. Earlier similar campaigns from North Korean-linked groups have also targeted crypto industry employees through fake job and interview processes.

According to Cisco Talos, the code of PylangGhost does not appear to be written with assistance from Artificial Intelligence. In April, hackers linked to the $1.4 billion Bybit theft targeted crypto developers using malware-laden recruitment tests, demonstrating the continued use of this tactic by North Korean-backed threat actors.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

NASA Shifts Artemis to Build $20B Permanent Moon Base

NASA has shifted its Artemis program strategy, now prioritizing the construction of a permanent...

War Sparks Cash Rush, Gold & Bonds Dumped

Bitcoin is under pressure as investors flee to cash, with Bitcoin retesting $67,500 support...

Circle Shares Plummet 20%; Tether Audit, Yield Bill Weigh

Circle's stock (CRCL) plummeted 20% on Tuesday, erasing recent gains.Rival Tether announced a major...

Robinhood announces $1.5B buyback plan over three years

Robinhood announced a new share repurchase program for up to $1.5 billion.The firm's shares...

Nearly All Pump Fun Traders Made Under $500

Over 96% of wallets trading Pump Fun-launched tokens have netted less than $500 in...

Must Read

9 Best Books On Ethereum And Blockchain Technology

QUICK LINKSHow to Choose Your First Blockchain Book: A Simple Framework1. Define Your Goal: Are you looking to Build, Invest, or Understand?2. Assess Your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading