Cybersecurity researchers have identified a social engineering campaign targeting cryptocurrency and Web3 professionals through fake job interviews designed to trick victims into installing remote access malware.
The campaign uses fraudulent recruitment approaches, including fake companies and impersonated organizations, to contact potential targets through professional networking platforms and invite them to complete what appear to be legitimate skills assessments. Researchers say the activity is part of a broader effort by North Korean-linked threat actors targeting individuals in the cryptocurrency sector.
During the fake assessment process, victims are directed through a series of steps that ultimately encourage them to copy and paste malicious commands onto their systems. The activity delivers malware designed to provide attackers with access to compromised devices and steal sensitive information.
The campaign targets both Windows and macOS users, deploying malware variants known as PylangGhost RAT and GolangGhost RAT. Researchers found that the malware includes multiple components designed to manage communication with attacker-controlled infrastructure, execute commands, and collect information from infected systems.
The attack chain uses social engineering techniques designed to create a sense of urgency and legitimacy. Fake assessment platforms include customized questions based on advertised job roles, video recording features, and simulated technical issues that pressure users into running malicious commands disguised as solutions to problems such as camera errors.
The latest campaign is associated with the North Korean-aligned threat actor known as Famous Chollima, also referred to as Wagemole, which has previously been linked to activity targeting cryptocurrency professionals through fake recruitment efforts.
According to analysis from the SOCRadar Threat Research Unit (STRU), the group’s latest “ClickFake Interview” campaign expands on previous recruitment-themed operations by using ClickFix-style techniques to distribute malware. The research found that attackers create multiple fake domains for fraudulent skill assessments, prioritizing speed and scale in deploying infrastructure.
The analysis found that the malware used in the campaign relies on multiple interconnected modules, including components responsible for configuration management, command execution, command-and-control communication, archiving, and information theft.
Researchers also identified efforts to make detection more difficult, including the use of additional programming techniques and runtime downloads required to operate the malware in victim environments.
The campaign highlights the continued use of social engineering against professionals working in cryptocurrency and emerging technology sectors, where attackers often attempt to exploit recruitment processes and professional networking activity to gain access to sensitive systems.
The full analysis can be read here.



