A sophisticated social engineering campaign aimed at Web3 and cryptocurrency professionals has recently come to light, according to researchers from SOCRadar. The campaign has been attributed to the notorious North Korean-aligned hacking group known as Famous Chollima, also referred to as Wagemole. This group has pivoted from traditional phishing tactics to intricate recruitment scams that exploit the growing mobility of tech talent in the cryptocurrency sector.
The modus operandi of Famous Chollima involves a calculated approach that begins with fraudulent job interviews. By establishing a facade of legitimacy, the group lures candidates into installing remote access trojans (RATs) on their devices. Unlike generic phishing attacks, this campaign focuses on personalized recruitment scams, thereby building trust with the targets before striking with malicious intent.
### Leveraging ClickFix Lures Within Broader Recruiter Schemes
The attack unfolds on various mainstream professional platforms such as LinkedIn, Telegram, Discord, and through direct emails. Pretending to be recruiters from reputable firms or under the guise of fictitious companies, the attackers entice developers and administrators with promises of lucrative salary packages and exciting job opportunities. Once potential candidates express interest, they are funneled into a mandatory skill assessment phase.
Upon agreeing to the assessment, candidates find themselves directed to a specialized online platform controlled by the hackers. These malicious interfaces are designed to create an illusion of authenticity through real-time monitoring techniques and psychometrics. Tailored interview questions, countdown timers, and strict gating mechanisms all add layers of psychological manipulation to keep the candidates engaged and stressed.
Moreover, candidates are met with automated warnings if they attempt to navigate away from the assessment page, effectively hindering their ability to cast suspicion on the operation. The crux of the deception lies in a hacking technique called ClickFix. While candidates participate in the assessment, the platform artificially instigates an error, claiming an inability to access the user’s camera or microphone.
To remedy this faux issue and advance in the interview process, the platform instructs candidates to copy and paste a diagnostic command into their system terminal. This technique plays on the target’s urgency to perform well, successfully bypassing standard security warnings.
### Infection Vectors for Windows and macOS Users
For victims operating on a Windows system, executing the copied command sets off a sophisticated infection chain. The malware, utilizing native Windows utilities like PowerShell or curl, fetches a compressed ZIP file from the attacker’s server. Subsequently, a Visual Basic Script silently unpacks a Python runtime, enabling the execution of PylangGhost, a customized RAT.
Conversely, macOS users face a similarly streamlined infection process, although the attack utilizes different programming languages. The malicious command aims to fetch and run GolangGhost, another form of RAT written in Go. In this case, the infection often installs a credential-harvesting helper application designed in SwiftUI, crafted to trick users into divulging their administrative passwords.
### Modular Architecture Designed for Maximum Impact
Both PylangGhost and GolangGhost are constructed on a modular architecture comprising six interconnected parts. These functionally distinct modules encompass a primary orchestrator, configuration holder, archive helper, command launcher, a command-and-control (C2) communications module, and a specialized data stealer. This modular setup allows the malware to execute commands efficiently, maintain persistence, and dynamically load new capabilities per instructions from the attackers.
The primary objective behind these malware suites is financial gain, specifically through asset theft. The integrated data stealer module has the capability to target over 80 browser extensions, especially those related to popular cryptocurrency wallets such as MetaMask, Phantom, and TronLink. This poses significant risks, as Web3 professionals often manage sensitive corporate infrastructures through browser-based tools. Consequently, a single successful incursion could result in the theft of millions of dollars’ worth of digital assets.
To facilitate their operations, Famous Chollima resorts to quickly registering domains via low-cost registrars like Hostinger and NameCheap. This approach enables them to create new phishing portals with exceptional speed, outpacing security measures that aim to blacklist compromised sites. The group employs rigorous targeting strategies, such as blocking mobile devices and validating invitation links, to obstruct automated malware sandboxes and security analysts from analyzing their delivery mechanisms.
In a recent report published on July 20, the SOCRadar Threat Research Unit (STRU) highlighted that this “ClickFake Interview” campaign poses risks not only to individual candidates but also to the organizations they represent. Researchers noted that many employees utilize company resources to apply for jobs or conduct interviews for external companies. This alarming trend increases the vulnerability of corporate funds and data, making it imperative for organizations to remain vigilant against such cunning and sophisticated cyber threats.

