GolangGhost Steals Chrome Secrets From macOS Keychain and Hijacks MetaMask Permissions
ID: fb73986b-bced-59ce-9660-e41b2ff90362
STIX ID: report--fb73986b-bced-59ce-9660-e41b2ff90362
Feed Name: cybersecurityNews.com
This report describes an active campaign attributed to North Korean-aligned Famous Chollima/Wagemole that targets cryptocurrency and Web3 professionals via fake interview pages; victims are tricked into pasting malicious commands that install GolangGhost on macOS (and PylangGhost on Windows). The malware steals browser credentials and wallet extension data (including MetaMask), abuses macOS Keychain, establishes persistence via Launch Agents, tampers with Chrome permissions to escalate access, and the report supplies domains, IPs, URLs, and numerous SHA-256 IoCs alongside recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
