Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros
ID: 39d05e12-19a0-5fac-a406-aba7e5cb129a
STIX ID: report--39d05e12-19a0-5fac-a406-aba7e5cb129a
Feed Name: Infosecurity Magazine (News)
Researchers at SOCRadar report a sophisticated, targeted campaign by North Korean-aligned Famous Chollima that uses fake recruiter outreach and interactive ‘ClickFake’ interview portals to trick Web3 professionals into executing terminal commands that install RATs (PylangGhost on Windows, GolangGhost on macOS). The malware suite is modular, compiled for evasion, and includes a stealer that targets browser wallet extensions and password managers to enable large-scale financial theft; the campaign uses rapid domain churn and gating to avoid detection and is actively being observed by researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
