North Korean-Linked Cyber Threat Campaign Targets Crypto and Web3 Professionals

Social engineering operation uses fraudulent recruitment processes to deliver malware targeting Windows and macOS systems

Cybersecurity researchers have identified a social engineering campaign targeting cryptocurrency and Web3 professionals through fake job interviews designed to trick victims into installing remote access malware.

The campaign uses fraudulent recruitment approaches, including fake companies and impersonated organizations, to contact potential targets through professional networking platforms and invite them to complete what appear to be legitimate skills assessments. Researchers say the activity is part of a broader effort by North Korean-linked threat actors targeting individuals in the cryptocurrency sector.

During the fake assessment process, victims are directed through a series of steps that ultimately encourage them to copy and paste malicious commands onto their systems. The activity delivers malware designed to provide attackers with access to compromised devices and steal sensitive information.

The campaign targets both Windows and macOS users, deploying malware variants known as PylangGhost RAT and GolangGhost RAT. Researchers found that the malware includes multiple components designed to manage communication with attacker-controlled infrastructure, execute commands, and collect information from infected systems.

The attack chain uses social engineering techniques designed to create a sense of urgency and legitimacy. Fake assessment platforms include customized questions based on advertised job roles, video recording features, and simulated technical issues that pressure users into running malicious commands disguised as solutions to problems such as camera errors.

The latest campaign is associated with the North Korean-aligned threat actor known as Famous Chollima, also referred to as Wagemole, which has previously been linked to activity targeting cryptocurrency professionals through fake recruitment efforts.

According to analysis from the SOCRadar Threat Research Unit (STRU), the group’s latest “ClickFake Interview” campaign expands on previous recruitment-themed operations by using ClickFix-style techniques to distribute malware. The research found that attackers create multiple fake domains for fraudulent skill assessments, prioritizing speed and scale in deploying infrastructure.

The analysis found that the malware used in the campaign relies on multiple interconnected modules, including components responsible for configuration management, command execution, command-and-control communication, archiving, and information theft.

Researchers also identified efforts to make detection more difficult, including the use of additional programming techniques and runtime downloads required to operate the malware in victim environments.

The campaign highlights the continued use of social engineering against professionals working in cryptocurrency and emerging technology sectors, where attackers often attempt to exploit recruitment processes and professional networking activity to gain access to sensitive systems.

The full analysis can be read here.

Matt Seldon, BSc., is an Editorial Associate with HSToday. He has over 20 years of experience in writing, social media, and analytics. Matt has a degree in Computer Studies from the University of South Wales in the UK. His diverse work experience includes positions at the Department for Work and Pensions and various responsibilities for a wide variety of companies in the private sector. He has been writing and editing various blogs and online content for promotional and educational purposes in his job roles since first entering the workplace. Matt has run various social media campaigns over his career on platforms including Google, Microsoft, Facebook and LinkedIn on topics surrounding promotion and education. His educational campaigns have been on topics including charity volunteering in the public sector and personal finance goals.

Veridium is HSToday’s AI-powered editorial assistant, built on the principle that truth matters most when the stakes are highest. Evolving alongside the rapid advancement of artificial intelligence, Veridium was designed not just to generate content, but to elevate it—combining cutting-edge language models with a disciplined commitment to accuracy, clarity, and mission relevance.

From its earliest iterations, Veridium has been rigorously trained to prioritize facts over narratives. It does not follow political trends or ideological framing; instead, it anchors its outputs in verified information, credible sourcing, and balanced analysis. Its development has been guided by a clear standard: to support journalism that informs rather than influences.

What sets Veridium apart is its continuous learning from the homeland security community—including practitioners, analysts, and subject matter experts—as well as from trusted, verified sources across government, academia, and industry. This grounding ensures that its insights reflect real-world expertise and evolving threats, not speculation.

As AI continues to transform how information is created and consumed, Veridium represents a deliberate path forward: technology in service of truth, built to support the integrity and mission of HSToday.

Related Articles

Latest Articles