North Korean ClickFake Campaign Targets Web3 Professionals with RATs

North Korean ClickFake Campaign Targets Web3 Professionals with RATs

First seen 22 Jul 2026, 10:52 UTC Infosecurity-MagazineGbhackers 73% similarity 72.5

Article Content

Browse articles
ThreatCluster

Researchers at SOCRadar have identified a new social engineering campaign by North Korea's Famous Chollima group, targeting Web3 and cryptocurrency professionals. The operation, dubbed ClickFake, employs fraudulent job interviews to lure candidates into executing malicious terminal commands. Victims are tricked into installing PylangGhost on Windows and GolangGhost on macOS via highly interactive web portals that simulate recruitment processes. The campaign uses platforms like Telegram and Discord to reach targets, offering lucrative job opportunities to entice them. Once engaged, candidates face psychological pressure through countdown timers and warnings against switching tabs. The attackers utilize advanced techniques to evade detection, including compiling their payloads into native dynamic link libraries. This targeted approach signifies a shift from broad phishing tactics to more personalized scams. The current status of the campaign remains active, with ongoing threats to the cryptocurrency sector.

Key Points: • North Korean hackers are targeting Web3 professionals through fake job interviews. • The ClickFake campaign deploys PylangGhost and GolangGhost RATs via malicious terminal commands. • Attackers utilize psychological tactics and advanced evasion techniques to deceive victims.

ThreatCluster AI

Timeline

2026-07-21
ClickFake campaign identified
SOCRadar researchers reported on a sophisticated social engineering operation by North Korea's Famous Chollima group targeting Web3 professionals.
Infosecurity-Magazine
2026-07-22
Gbhackers report on ClickFake campaign
Gbhackers published details about the ClickFake Interview operation, confirming the use of PylangGhost and GolangGhost RATs.
Gbhackers

Community

Browse all →