North Korea targets crypto workers with new info-stealing malware

Key Points

  • North Korean Threat: A North Korean-aligned hacking group, "Famous Chollima" or "Wagemole," is targeting crypto industry professionals with a new Python-based malware called "PylangGhost."**
  • Fake Job Sites: Attackers use fraudulent job websites mimicking legitimate companies like Coinbase and Uniswap to lure victims through fake interviews and skill tests.**
  • Malware Capabilities: PylangGhost, a variant of GolangGhost, steals credentials from over 80 browser extensions, including crypto wallets like MetaMask and password managers.**
  • Social Engineering Tactics: Victims are tricked into executing malicious commands during fake interviews, often under the guise of installing video drivers.**
  • Broader Impact: The malware also enables remote control, file management, screenshot capture, and data theft from infected systems.**

Summary

North Korean hackers, linked to the group "Famous Chollima" or "Wagemole," are targeting cryptocurrency and blockchain professionals with a new Python-based malware named "PylangGhost," according to a Cisco Talos report. The attackers deploy social engineering tactics through fake job websites impersonating reputable firms like Coinbase and Uniswap, primarily focusing on individuals in India. Victims are lured into multi-step processes involving fake interviews and skill tests, during which they are tricked into executing malicious commands, compromising their devices. PylangGhost, a variant of the earlier GolangGhost, can steal credentials from over 80 browser extensions, including crypto wallets like MetaMask and password managers. Beyond credential theft, the malware supports remote access, file management, and data collection, posing a significant threat to infected systems. This is not the first instance of such tactics, as similar fake job lures were linked to the $1.4 billion Bybit heist in April. The ongoing campaign highlights the persistent and evolving threat of North Korean cyber actors targeting the crypto industry.

cointelegraph
June 20, 2025
Crypto
Read article

Related news