logo

North Korean ClickFake Campaign Targets Web3 Professionals with RATs

ID: c0287ee1-4d83-5d3d-b43d-c842c1e724dd

STIX ID: report--c0287ee1-4d83-5d3d-b43d-c842c1e724dd

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

Researchers attribute an active campaign named ClickFake to North Korea’s Chollima group that lures Web3 and crypto professionals with fake job interviews on Telegram and Discord, coercing victims into running malicious terminal commands. The operation deploys PylangGhost on Windows and GolangGhost on macOS via interactive web portals, employs psychological pressure (countdowns, tab-switch warnings), and uses evasion techniques such as native DLL compilation, posing a targeted threat to cryptocurrency sector personnel and infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.